CVE-2020-3337: Cisco Umbrella Open Redirect Vulnerability
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request that could cause the web application to redirect the request to a specified malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3337?
CVE-2020-3337 has been rated as a medium severity vulnerability.
How do I fix CVE-2020-3337?
To mitigate CVE-2020-3337, ensure that you have applied the latest patches and updates provided by Cisco for Umbrella services.
Who is affected by CVE-2020-3337?
CVE-2020-3337 affects users of Cisco Umbrella services who have not properly secured their configurations.
Can CVE-2020-3337 be exploited remotely?
Yes, CVE-2020-3337 can be exploited remotely by an unauthenticated attacker.
What type of attack does CVE-2020-3337 facilitate?
CVE-2020-3337 facilitates open redirect attacks, allowing attackers to redirect users to malicious websites.