6.1
CVE-2021-38123
- EPSS 0.23%
- Veröffentlicht 07.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:25
- Quelle security@opentext.com
- CVE-Watchlists
- Unerledigt
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Network Automation Version10.40
Microfocus ≫ Network Automation Version10.50
Microfocus ≫ Network Automation Version2018.05
Microfocus ≫ Network Automation Version2018.11
Microfocus ≫ Network Automation Version2019.05
Microfocus ≫ Network Automation Version2020.02
Microfocus ≫ Network Automation Version2020.08
Microfocus ≫ Network Automation Version2020.11
Microfocus ≫ Network Automation Version2021.05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.433 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.