CVE-2019-727501.07.2019, 20:15Optergy Proton/Enterprise devices allow Open Redirect.Open RedirectEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.1 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 97%VendorProductVersionoptergyenterprise𝑥≤ 2.3.0aoptergyproton𝑥≤ 2.3.0a𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-601 - URL Redirection to Untrusted Site ('Open Redirect')A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.Referenceshttp://packetstormsecurity.com/files/155268/Optergy-Proton-Enterprise-BMS-2.3.0a-Open-Redirect.htmlhttp://www.securityfocus.com/bid/108686https://applied-risk.com/labs/advisorieshttps://www.applied-risk.com/resources/ar-2019-008http://packetstormsecurity.com/files/155268/Optergy-Proton-Enterprise-BMS-2.3.0a-Open-Redirect.htmlhttp://www.securityfocus.com/bid/108686https://applied-risk.com/labs/advisorieshttps://www.applied-risk.com/resources/ar-2019-008