Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1251

Опубликовано: 28 сент. 2018
Источник: nvd
CVSS3: 8.3
CVSS3: 8.1
CVSS2: 5.8
EPSS Низкий

Описание

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dell:emc_unity_firmware:*:*:*:*:*:*:*:*
Версия до 4.3.1.1525703027 (исключая)
cpe:2.3:h:dell:emc_unity:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:dell:emc_unityvsa:*:*:*:*:*:*:*:*
Версия до 4.3.1.1525703027 (исключая)

EPSS

Процентиль: 53%
0.003
Низкий

8.3 High

CVSS3

8.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.

EPSS

Процентиль: 53%
0.003
Низкий

8.3 High

CVSS3

8.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601