CVE-2022-44718
Last modified
CVE-2022-44718 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Netscout | Ngeniusone | 6.3.2 | Build904 |
References
- https://www.netscout.com/securityadvisoriesVendor Advisory
- https://www.netscout.com/securityadvisoriesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-44718?
How severe is CVE-2022-44718?
How do I fix CVE-2022-44718?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-44708Microsoft Edge (Chromium-based) Elevation of Privilege Vulne…8.3
- CVE-2022-4471The YARPP WordPress plugin before 5.30.3 does not validate a…5.4
- CVE-2022-44710DirectX Graphics Kernel Elevation of Privilege Vulnerability7.8
- CVE-2022-44713Microsoft Outlook for Mac Spoofing Vulnerability7.5
- CVE-2022-44715Improper File Permissions in NetScout nGeniusONE 6.3.2 build…8.8
- CVE-2022-44717An issue was discovered in NetScout nGeniusONE 6.3.2 build 9…3.1
- CVE-2022-44719An issue was discovered in Weblib Ucopia before 6.0.13. The …7.5
- CVE-2022-4472The Simple Sitemap WordPress plugin before 3.5.8 does not va…5.4
- CVE-2022-44720An issue was discovered in Weblib Ucopia before 6.0.13. OS C…9.8
- CVE-2022-44721Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-44724The Handy Tip macro in Stiltsoft Handy Macros for Confluence…5.4
- CVE-2022-44725OPC Foundation Local Discovery Server (LDS) through 1.04.403…7.8
Are you affected by CVE-2022-44718?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
