Impact
The vulnerability enables an attacker to supply a manipulated URL parameter that is reflected by the server without adequate validation, resulting in an open redirect. This flaw permits the redirection of users to a malicious site of the attacker's choosing, potentially enabling phishing, credential theft, or malicious content delivery. The weakness is a classic open redirect, reflected in the CWE-601 class of flaws, and affects the confidentiality and integrity of user navigation but does not grant direct execution or system control.
Affected Systems
Nokia NSP is affected. Specific product versions are not disclosed, so any deployment of the NSP product line should be considered vulnerable until a vendor‑issued patch is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is <1%, and the vulnerability is not listed in CISA’s KEV catalog, which suggests limited publicly known exploitation. The attack vector relies on a malicious actor embedding a crafted redirect URL in a link or form that a user can click or submit. If the redirect is not properly validated, the user is automatically forwarded to the attacker‑controlled destination, enabling further social‑engineering attacks.
OpenCVE Enrichment