ID

VAR-201704-0071


CVE

CVE-2016-10316


TITLE

plural Jensen of Scandinavia AS Air:Link Open redirect vulnerability in devices

Trust: 0.8

sources: JVNDB: JVNDB-2016-008248

DESCRIPTION

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-url parameter to /goform/formLogout. Air: Link3G, Air: Link5000AC, Air: Link59300 is the router of the Norwegian Jensenof Scandinavia company. An attacker can construct a malicious URI, entice the user to resolve, and redirect the user to any WEB site for phishing attacks. are all routers of Jensen of Scandinavia AS in Norway. Several Jensen of Scandinavia AS Air:Link products have security vulnerabilities. 3); Air: Link 5000AC (AL5000AC) prior to 1.13; Air: Link 59300 (AL59300) 1.04 (Rev

Trust: 2.25

sources: NVD: CVE-2016-10316 // JVNDB: JVNDB-2016-008248 // CNVD: CNVD-2017-05306 // VULHUB: VHN-89080

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-05306

AFFECTED PRODUCTS

vendor:jensenofscandinaviamodel:al3gscope:eqversion:2.23m

Trust: 1.6

vendor:jensenofscandinaviamodel:al5000acscope:eqversion:1.13

Trust: 1.6

vendor:jensenofscandinaviamodel:al59300scope:eqversion:1.04

Trust: 1.6

vendor:jensen of scandinavia asmodel:air:link 3gscope:eqversion:2.23m (rev.3)

Trust: 0.8

vendor:jensen of scandinavia asmodel:air:link 5000acscope:eqversion:1.13

Trust: 0.8

vendor:jensen of scandinavia asmodel:air:link 59300scope:eqversion:1.04 (rev.4)

Trust: 0.8

vendor:jensenmodel:of scandinavia air:link 3g 2.23m (rev.scope:eqversion:3)

Trust: 0.6

vendor:jensenmodel:of scandinavia air:link 5000acscope:eqversion:1.13

Trust: 0.6

vendor:jensenmodel:of scandinavia air:link (rev.scope:eqversion:593001.044)

Trust: 0.6

sources: CNVD: CNVD-2017-05306 // JVNDB: JVNDB-2016-008248 // CNNVD: CNNVD-201704-172 // NVD: CVE-2016-10316

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-10316
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-10316
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-05306
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201704-172
value: MEDIUM

Trust: 0.6

VULHUB: VHN-89080
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-10316
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-05306
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-89080
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-10316
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-05306 // VULHUB: VHN-89080 // JVNDB: JVNDB-2016-008248 // CNNVD: CNNVD-201704-172 // NVD: CVE-2016-10316

PROBLEMTYPE DATA

problemtype:CWE-601

Trust: 1.9

sources: VULHUB: VHN-89080 // JVNDB: JVNDB-2016-008248 // NVD: CVE-2016-10316

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-172

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201704-172

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-008248

PATCH

title:Top Pageurl:http://www.jensenofscandinavia.com

Trust: 0.8

title:Multiple JensenofScandinaviaAir: Link \342\200\230return-url\342\200\231 parameter open redirect vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/92435

Trust: 0.6

sources: CNVD: CNVD-2017-05306 // JVNDB: JVNDB-2016-008248

EXTERNAL IDS

db:NVDid:CVE-2016-10316

Trust: 3.1

db:JVNDBid:JVNDB-2016-008248

Trust: 0.8

db:CNNVDid:CNNVD-201704-172

Trust: 0.7

db:CNVDid:CNVD-2017-05306

Trust: 0.6

db:VULHUBid:VHN-89080

Trust: 0.1

sources: CNVD: CNVD-2017-05306 // VULHUB: VHN-89080 // JVNDB: JVNDB-2016-008248 // CNNVD: CNNVD-201704-172 // NVD: CVE-2016-10316

REFERENCES

url:https://www.riskbasedsecurity.com/research/rbs-2016-004.pdf

Trust: 3.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-10316

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-10316

Trust: 0.8

sources: CNVD: CNVD-2017-05306 // VULHUB: VHN-89080 // JVNDB: JVNDB-2016-008248 // CNNVD: CNNVD-201704-172 // NVD: CVE-2016-10316

SOURCES

db:CNVDid:CNVD-2017-05306
db:VULHUBid:VHN-89080
db:JVNDBid:JVNDB-2016-008248
db:CNNVDid:CNNVD-201704-172
db:NVDid:CVE-2016-10316

LAST UPDATE DATE

2025-04-20T23:34:27.915000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-05306date:2017-04-25T00:00:00
db:VULHUBid:VHN-89080date:2017-04-10T00:00:00
db:JVNDBid:JVNDB-2016-008248date:2017-05-08T00:00:00
db:CNNVDid:CNNVD-201704-172date:2017-04-07T00:00:00
db:NVDid:CVE-2016-10316date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-05306date:2017-04-25T00:00:00
db:VULHUBid:VHN-89080date:2017-04-03T00:00:00
db:JVNDBid:JVNDB-2016-008248date:2017-05-08T00:00:00
db:CNNVDid:CNNVD-201704-172date:2017-04-07T00:00:00
db:NVDid:CVE-2016-10316date:2017-04-03T05:59:00.677