Open Redirect Vulnerability in Fortinet FortiWeb Product
CVE-2021-43064

4.3MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
8 December 2021

Summary

An open redirect vulnerability in Fortinet FortiWeb allows attackers to redirect users to untrusted sites. This flaw impacts FortiWeb versions 6.4.1, 6.4.0, and earlier versions, enabling malicious actors to use the device as a proxy, granting access to external or protected hosts through manipulated redirection handlers. Organizations using affected versions are advised to implement security measures and updates to mitigate potential exploitation.

Affected Version(s)

Fortinet FortiWeb FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.