CVE-2021-36191

MEDIUM

Fortinet FortiWeb <6.4.1-6.3.15 - Open Redirect

Title source: llm
STIX 2.1

Description

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-133

Scores

CVSS v3 4.1
EPSS 0.0022
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (6)
fortinet/fortiweb 6.1.0
fortinet/fortiweb 6.1.1
fortinet/fortiweb 6.1.2
fortinet/fortiweb 6.4.0
fortinet/fortiweb 6.4.1
fortinet/fortiweb 6.0.0 - 6.0.7
Published Dec 08, 2021
Tracked Since Feb 18, 2026