First published: Thu Jun 18 2020(Updated: )
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request that could cause the web application to redirect the request to a specified malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious website.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Umbrella |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3337 has been rated as a medium severity vulnerability.
To mitigate CVE-2020-3337, ensure that you have applied the latest patches and updates provided by Cisco for Umbrella services.
CVE-2020-3337 affects users of Cisco Umbrella services who have not properly secured their configurations.
Yes, CVE-2020-3337 can be exploited remotely by an unauthenticated attacker.
CVE-2020-3337 facilitates open redirect attacks, allowing attackers to redirect users to malicious websites.