Record summary

CVE-2019-7275 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Optergy Proton/Enterprise devices allow Open Redirect.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOptergy Proton/Enterprise Building Management System - Open RedirectCVSS 6.1

Optergy Proton/Enterprise Building Management System contains an open redirect vulnerability. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.

Remediation

Apply the latest security patches or updates provided by Optergy to fix the open redirect vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2019redirectpacketstormoptergyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:optergy:enterprise:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5