CVE-2020-8430
MEDIUMStormshield Network Security 310 3.7.10 - Open Redirect
Title source: llmDescription
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.
References (4)
Core 4
Core References
Product, Vendor Advisory x_refsource_misc
https://www.stormshield.com/products/sn310/
Broken Link x_refsource_misc
https://www.digitemis.com/category/blog/actualite/
Third Party Advisory x_refsource_misc
https://www.digitemis.com/2020/02/24/digitemis-decouvre-une-vulnerabilite-au-sein-dun-produit-stormshield-cve-2020-8430/
Vendor Advisory x_refsource_confirm
https://advisories.stormshield.eu/2020-001/
Scores
CVSS v3
6.1
EPSS
0.0092
EPSS Percentile
55.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (1)
stormshield/stormshield_network_security
3.0.0 - 3.7.10
Published
Apr 13, 2020
Tracked Since
Feb 18, 2026