cbcvebase.
CVE-2023-22641
published 2023-04-11

CVE-2023-22641: A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions…

PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.30%
21.7th percentile
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows an authenticated attacker to execute unauthorized code or commands via specially crafted requests.

Affected

19 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios>= 6.0.0 < 6.4.136.4.13
fortinetfortios6.0.0 – 6.0.16
fortinetfortios6.2.0 – 6.2.13
fortinetfortios6.4.0 – 6.4.12
fortinetfortios>= 7.0.0 < 7.0.117.0.11
fortinetfortios7.0.0 – 7.0.9
fortinetfortios>= 7.2.0 < 7.2.47.2.4
fortinetfortios7.2.0 – 7.2.3
fortinetfortiproxy
fortinetfortiproxy1.0.0 – 2.0.12
fortinetfortiproxy1.1.0 – 1.1.6
fortinetfortiproxy1.2.0 – 1.2.13
fortinetfortiproxy2.0.0 – 2.0.12
fortinetfortiproxy>= 7.0.0 < 7.0.97.0.9
fortinetfortiproxy7.0.0 – 7.0.8
fortinetfortiproxy>= 7.2.0 < 7.2.37.2.3
fortinetfortiproxy7.2.0 – 7.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.