packetstormsecurity.com
http://packetstormsecurity.com/files/155268/Optergy-Proton-Enterprise-BMS-2.3.0a-Open-Redirect.html CVE-2019-7275
MEDIUMNuclei
Optergy Proton/Enterprise Building Management System - Open Redirect
Record summary
CVE-2019-7275 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Optergy Proton/Enterprise devices allow Open Redirect.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMOptergy Proton/Enterprise Building Management System - Open RedirectCVSS 6.1
Optergy Proton/Enterprise Building Management System contains an open redirect vulnerability. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.
Remediation
Apply the latest security patches or updates provided by Optergy to fix the open redirect vulnerability.
WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2019redirectpacketstormoptergyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:optergy:enterprise:*:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/155268/Optergy-Proton-Enterprise-BMS-2.3.0a-Open-Redirect.html https://applied-risk.com/resources/ar-2019-008 https://cxsecurity.com/issue/WLB-2019110074 https://applied-risk.com/labs/advisories https://nvd.nist.gov/vuln/detail/CVE-2019-7275
Source: ProjectDiscovery
References
5108686vdb entry
http://www.securityfocus.com/bid/108686 applied-risk.com
https://applied-risk.com/labs/advisories nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-7275 applied-risk.com
https://www.applied-risk.com/resources/ar-2019-008