First published: Mon Apr 13 2020(Updated: )
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stormshield Stormshield Network Security | >=3.0.0<=3.7.10 | |
Stormshield Stormshield Network Security | >=3.8.0<=3.10.0 | |
Stormshield Stormshield Network Security | >=4.0.0<=4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8430 is an Open Redirect vulnerability found in Stormshield Network Security 310 3.7.10 devices.
The CVE-2020-8430 vulnerability affects Stormshield Network Security devices by allowing an attacker to perform open redirects on the captive portal.
The severity of CVE-2020-8430 is medium with a CVSS score of 6.1.
To fix the CVE-2020-8430 vulnerability, it is recommended to update Stormshield Network Security devices to a version that is not affected.
You can find more information about the CVE-2020-8430 vulnerability on the Stormshield advisories website and the Digitemis blog.