Open Redirect Vulnerability in Fortinet FortiWeb Product
CVE-2021-43064
4.3MEDIUM
Summary
An open redirect vulnerability in Fortinet FortiWeb allows attackers to redirect users to untrusted sites. This flaw impacts FortiWeb versions 6.4.1, 6.4.0, and earlier versions, enabling malicious actors to use the device as a proxy, granting access to external or protected hosts through manipulated redirection handlers. Organizations using affected versions are advised to implement security measures and updates to mitigate potential exploitation.
Affected Version(s)
Fortinet FortiWeb FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved