CVE-2022-43950Open Redirect in Fortinet Fortinac

CWE-601Open Redirect4 documents4 sources
Severity
4.7MEDIUMNVD
CNA4.3
EPSS
0.2%
top 54.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateMay 4

Description

A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDfortinet/fortinac8.7.09.4.2
CVEListV5fortinet/fortinac9.4.09.4.1+4

🔴Vulnerability Details

2
GHSA
GHSA-4jvr-8wq7-595q: A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 72023-05-04
CVEList
CVE-2022-43950: A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 72023-05-03

📋Vendor Advisories

1
Fortinet
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC vers...2023-05-03
CVE-2022-43950 — Open Redirect in Fortinet Fortinac | cvebase