VulnerabilityModified
CVE-2023-37624
Netdisco before v2.063000 was discovered to contain an open redirect vulnerability.
MEDIUM 6.1EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- netdisco/netdisco
- Source
- cve@mitre.org
References
- https://github.com/benjaminpsinclair/Netdisco-2023-AdvisoryExploit
- https://github.com/benjaminpsinclair/Netdisco-CVEExploit
- https://github.com/netdisco/netdisco/commit/a2da6a7a046c1c0fd41072dd6991eec7614293f8Patch
- https://github.com/benjaminpsinclair/Netdisco-2023-AdvisoryExploit
- https://github.com/benjaminpsinclair/Netdisco-CVEExploit
- https://github.com/netdisco/netdisco/commit/a2da6a7a046c1c0fd41072dd6991eec7614293f8Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.