CVE-2024-28344
LOWCVSS 3.1/10EPSS 0.46%
Last modified
CVE-2024-28344 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sipwise | Next Generation Communication Platform | < mr11.5.1 |
References
- https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/Exploit, Third Party Advisory
- https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-28344?
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.
How severe is CVE-2024-28344?
CVE-2024-28344 has a CVSS score of 3.1/10 (LOW severity). The EPSS model estimates a 0.46% probability of exploitation in the next 30 days.
How do I fix CVE-2024-28344?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2833The Jobs for WordPress plugin for WordPress is vulnerable to…6.1
- CVE-2024-28335Lektor before 3.3.11 does not sanitize DB path traversal. Th…9.1
- CVE-2024-28338A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allo…8
- CVE-2024-28339An information leak in the debuginfo.htm component of Netgea…5.4
- CVE-2024-2834A Stored Cross-Site Scripting (XSS) vulnerability has been i…8.7
- CVE-2024-28340An information leak in the currentsetting.htm component of N…7.5
- CVE-2024-28345An issue discovered in Sipwise C5 NGCP Dashboard below mr11.…5.5
- CVE-2024-2835A Stored Cross-Site Scripting (XSS) vulnerability has been i…8.7
- CVE-2024-28353There is a command injection vulnerability in the TRENDnet T…8.8
- CVE-2024-28354There is a command injection vulnerability in the TRENDnet T…10
- CVE-2024-2836The Social Share, Social Login and Social Comments Plugin W…4.8
- CVE-2024-2837The WP Chat App WordPress plugin before 3.6.4 does not sanit…5.4
Are you affected by CVE-2024-28344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
