CVE-2024-6377
Last modified
CVE-2024-6377 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| 3ds | 3dexperience | >= r2022x, <= r2024x |
References
- https://www.3ds.com/vulnerability/advisoriesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-6377?
How severe is CVE-2024-6377?
How do I fix CVE-2024-6377?
Are you affected by CVE-2024-6377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
