Lucene search

K
cve[email protected]CVE-2023-5629
HistoryDec 14, 2023 - 5:15 a.m.

CVE-2023-5629

2023-12-1405:15:12
CWE-601
web.nvd.nist.gov
15
cwe-601
url redirection
open redirect
phishing
http
nvd
cve-2023-5629

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could
cause disclosure of information through phishing attempts over HTTP.

Affected configurations

NVD
Node
schneider-electriceb450Match-
AND
schneider-electriceb450_firmwareMatch-
Node
schneider-electriceb45eMatch-
AND
schneider-electriceb45e_firmwareMatch-
Node
schneider-electriceh450Match-
AND
schneider-electriceh450_firmwareMatch-
Node
schneider-electriceh45eMatch-
AND
schneider-electriceh45e_firmwareMatch-
Node
schneider-electricer450_firmwareMatch-
AND
schneider-electricer450Match-
Node
schneider-electricer45e_firmwareMatch-
AND
schneider-electricer45eMatch-
Node
schneider-electricjr240_firmwareMatch-
AND
schneider-electricjr240Match-
Node
schneider-electricjr900_firmwareMatch-
AND
schneider-electricjr900Match-
Node
schneider-electricqr450_firmwareRange<2.7.0
AND
schneider-electricqr450Match-
Node
schneider-electricqr150_firmwareRange<2.7.0
AND
schneider-electricqr150Match-
Node
schneider-electricqb450_firmwareRange<2.7.0
AND
schneider-electricqb450Match-
Node
schneider-electricqb150_firmwareRange<2.7.0
AND
schneider-electricqb150Match-
Node
schneider-electricqp450_firmwareRange<2.7.0
AND
schneider-electricqp450Match-
Node
schneider-electricqp150_firmwareRange<2.7.0
AND
schneider-electricqp150Match-
Node
schneider-electricqh450_firmwareRange<2.7.0
AND
schneider-electricqh450Match-
Node
schneider-electricqh150_firmwareRange<2.7.0
AND
schneider-electricqh150Match-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Trio Q-Series Ethernet Data Radio",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "status": "affected",
        "version": "Versions prior to 2.7.0"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Trio E-Series Ethernet Data Radio",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "status": "affected",
        "version": "All versions of models ER45e, EB45e, EH45e"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Trio J-Series Ethernet Data Radio",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "status": "affected",
        "version": "All Versions"
      }
    ]
  }
]

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Related for CVE-2023-5629