Overview
- Description
- A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL.
- Source
- psirt@fortinet.com
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.7
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- Severity
- MEDIUM
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A30BF9D-B074-42C5-8C46-15651E379371", "versionEndExcluding": "9.4.2", "versionStartIncluding": "8.7.0" }, { "criteria": "cpe:2.3:a:fortinet:fortinac-f:7.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77DE647F-0252-42E2-8BDD-C98DC899C613" } ], "operator": "OR" } ] } ]