CVE-2023-50704 MEDIUM

CVE-2023-50704: URL Redirection to Untrusted Site ('Open Redirect') in EFACEC UC 500E

Vendor Efacec
Product UC 500E
Weakness CWE-601 · Open redirect
Published December 19, 2023
Last update September 16, 2024

CVSS base score

4.3/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.

Key dates

02Disclosure timeline

December 19, 2023 CVE published
September 16, 2024 Record updated