CVE-2022-44717
Last modified
CVE-2022-44717 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Netscout | Ngeniusone | 6.3.2 | Build904 |
References
- https://www.netscout.com/securityadvisoriesVendor Advisory
- https://www.netscout.com/securityadvisoriesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-44717?
How severe is CVE-2022-44717?
How do I fix CVE-2022-44717?
Are you affected by CVE-2022-44717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
