Vulnerability Description
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiweb | >= 6.2.0, <= 6.2.6 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/advisory/FG-IR-21-168PatchVendor Advisory
- https://fortiguard.com/advisory/FG-IR-21-168PatchVendor Advisory
FAQ
What is CVE-2021-43064?
CVE-2021-43064 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and r...
How severe is CVE-2021-43064?
CVE-2021-43064 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43064?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiweb.