6.1

CVE-2021-38123

Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Network Automation Version 10.40
Microfocus ≫ Network Automation Version 10.50
Microfocus ≫ Network Automation Version 2018.05
Microfocus ≫ Network Automation Version 2018.11
Microfocus ≫ Network Automation Version 2019.05
Microfocus ≫ Network Automation Version 2020.02
Microfocus ≫ Network Automation Version 2020.08
Microfocus ≫ Network Automation Version 2020.11
Microfocus ≫ Network Automation Version 2021.05
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.464
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.