IM
IronMonkey Threat Research

CVE-2017-5571 MEDIUM

Published: 2017-03-03 | Last Modified: 2026-06-17 | Status: Modified

Description

Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Additional Descriptions (1)

Vulnerabilidad de redirección abierta en el componente lmadmin en Flexera FlexNet Publisher (también conocido como Flex License Manager) 11.14.1 y versiones anteriores, como se utiliza en Citrix License Server para Windows y el Citrix License Server VPX, permite a atacantes remotos redirigir a usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de vectores no especificados.

CVSS Metrics

Base Score: 5.8 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:P/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 4.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-601

Affected Products

Vendor Product Version Update Type
flexerasoftware flexnet_publisher * <built-in method update of dict object at 0x7e60b8460880> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:flexerasoftware:flexnet_publisher:*:*:*:*:*:*:*:*
Notification
Message here