QID 44047
Date Published: 2023-05-31
QID 44047: Fortinet FortiOS Unauthorized Code Vulnerability (FG-IR-22-479) (Unauthenticated Check)
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiOS and FortiProxy sslvpnd may allow an authenticated attacker to redirect users to any arbitrary website via a crafted URL.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.12
FortiOS all versions 6.2, 6.0
QID Detection Logic (No Auth):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform an Execute unauthorized code or commands.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-479
Vendor References
- FG-IR-22-479 -
www.fortiguard.com/psirt/FG-IR-22-479
CVEs related to QID 44047
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-479 |
|