Description
A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.
Problem types
URL Redirection to Untrusted Site ('Open Redirect')
Product status
1.4.0.0
2.1.1.0
2.1.1.3
2.1.2.0
2.1.2.3
2.1.2.4
2.1.2.5
2.2.1.0
2.1.2.6
2.2.2.0
2.2.2.1
2.2.2.3
2.1.2.7
2.2.1.3
2.2.3.0
2.2.2.4
2.2.2.5
2.2.3.3
2.2.2.7
2.2.2.6
2.2.2.8
2.2.3.4
2.1.2.8
2.3.2.1
2.3.2.1-AIRGAP
2.3.2.1-AIRGAP-CA
2.2.3.5
2.3.3.0
2.3.3.3
2.3.3.1-AIRGAP
2.3.3.1
2.3.2.3
2.3.3.3-AIRGAP
2.2.3.6
2.2.2.9
2.3.3.0-AIRGAP
2.3.3.3-AIRGAP-CA
2.3.3.4
2.3.3.4-AIRGAP
2.3.3.4-AIRGAP-MDNAC
2.3.3.4-HF1
2.3.4.0
2.3.3.5
2.3.3.5-AIRGAP
2.3.4.0-AIRGAP
2.3.4.3
2.3.4.3-AIRGAP
2.3.3.6
2.3.5.0
2.3.3.6-AIRGAP
2.3.5.0-AIRGAP
2.3.3.6-AIRGAP-MDNAC
2.3.5.0-AIRGAP-MDNAC
2.3.3.7
2.3.3.7-AIRGAP
2.3.3.7-AIRGAP-MDNAC
2.3.6.0
2.3.3.6-70045-HF1
2.3.3.7-72328-AIRGAP
2.3.3.7-72323
2.3.3.7-72328-MDNAC
2.3.5.3
2.3.5.3-AIRGAP-MDNAC
2.3.5.3-AIRGAP
2.3.6.0-AIRGAP
2.3.7.0
2.3.7.0-AIRGAP
2.3.7.0-AIRGAP-MDNAC
2.3.7.0-VA
2.3.5.4
2.3.5.4-AIRGAP
2.3.5.4-AIRGAP-MDNAC
2.3.7.3
2.3.7.3-AIRGAP
2.3.7.3-AIRGAP-MDNAC
2.3.5.5-AIRGAP
2.3.5.5
2.3.5.5-AIRGAP-MDNAC
2.3.7.4
2.3.7.4-AIRGAP
2.3.7.4-AIRGAP-MDNAC
2.3.7.5-AIRGAP
2.3.7.5-VA
2.3.5.6-AIRGAP
2.3.5.6
2.3.5.6-AIRGAP-MDNAC
1.0.0.0
2.3.7.6-AIRGAP
2.3.7.6
2.3.7.6-VA
2.3.5.5-70026-HF70
2.3.5.5-70026-HF51
2.3.5.6-70143-HF20
2.3.7.6-AIRGAP-MDNAC
2.3.5.5-70026-HF52
2.3.5.5-70026-HF53
2.3.5.5-70026-HF71
2.3.7.7
2.3.7.7-VA
2.3.7.7-AIRGAP
2.3.7.7-AIRGAP-MDNAC
2.3.5.5-70026-HF72
2.3.7.9-VA
2.3.7.9
2.3.7.9-AIRGAP
2.3.7.9-AIRGAP-MDNAC
2.3.7.9-70301-GSMU10
2.3.7.9-75403-SMU10
2.3.7.9-75403-GSMU10
2.3.7.9.75403.10-VA
References
sec.cloudapps.cisco.com/...co-sa-catc-open-redirect-3W5Bk3Je (cisco-sa-catc-open-redirect-3W5Bk3Je)