Vulnerability Description
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows an authenticated attacker to execute unauthorized code or commands via specially crafted requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiproxy | >= 1.0.0, <= 2.0.12 |
| Fortinet | Fortios | >= 6.0.0, < 6.4.13 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-22-479Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-22-479Vendor Advisory
FAQ
What is CVE-2023-22641?
CVE-2023-22641 is a vulnerability with a CVSS score of 4.1 (MEDIUM). A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions ...
How severe is CVE-2023-22641?
CVE-2023-22641 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22641?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiproxy, Fortinet Fortios.