6.1
CVE-2016-9099
- EPSS 0.31%
- Published 11.05.2017 14:30:16
- Last modified 20.04.2025 01:37:25
- Source secure@symantec.com
- Teams watchlist Login
- Open Login
Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to redirect the target user to a malicious web site.
Data is provided by the National Vulnerability Database (NVD)
Broadcom ≫ Advanced Secure Gateway Version >= 6.7 < 6.7.2.1
Broadcom ≫ Symantec Proxysg Version >= 6.5 < 6.5.10.6
Broadcom ≫ Advanced Secure Gateway Version6.6
Broadcom ≫ Symantec Proxysg Version6.6
Broadcom ≫ Symantec Proxysg Version >= 6.7 < 6.7.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.31% | 0.513 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.