CVE-2017-9296: Medium severity Hitachi Device Manager vulnerability
Published May 29, 2017
·Updated
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.
Affected Software
1 affected component
Hitachi Device Manager<=8.5.2
Event History
May 29, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9296?
CVE-2017-9296 has a medium severity rating due to its potential for exploitation through redirection to malicious websites.
2
How do I fix CVE-2017-9296?
To fix CVE-2017-9296, upgrade to Hitachi Device Manager version 8.5.2-01 or later.
3
What types of attacks can CVE-2017-9296 enable?
CVE-2017-9296 can enable remote attackers to conduct phishing attacks and redirect users to malicious sites.
4
What products are affected by CVE-2017-9296?
CVE-2017-9296 affects Hitachi Device Manager versions prior to 8.5.2-01 and Hitachi Tuning Manager versions prior to 8.5.2-00.
5
Is authentication required to exploit CVE-2017-9296?
Yes, exploitation of CVE-2017-9296 requires the attacker to target authenticated users.