6.1
CVE-2021-38123
- EPSS 0.65%
- Veröffentlicht 07.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:25
- Erkennungen
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Network Automation Version 10.40
Microfocus ≫ Network Automation Version 10.50
Microfocus ≫ Network Automation Version 2018.05
Microfocus ≫ Network Automation Version 2018.11
Microfocus ≫ Network Automation Version 2019.05
Microfocus ≫ Network Automation Version 2020.02
Microfocus ≫ Network Automation Version 2020.08
Microfocus ≫ Network Automation Version 2020.11
Microfocus ≫ Network Automation Version 2021.05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.65% | 0.464 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://portal.microfocus.com/s/article/KM000001673