CVE-2016-10316 Information

Description

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3) Air:Link 5000AC (AL5000AC) version 1.13 and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-url parameter to /goform/formLogout.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://www.riskbasedsecurity.com/research/RBS-2016-004.pdf Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3) Air:Link 5000AC (AL5000AC) version 1.13 and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-url parameter to /goform/formLogout.

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: