CVE-2022-43950

MEDIUM

FortiNAC-F <7.2.0, FortiNAC <9.4.1, 9.2 all, 9.1 all, 8.8 all, 8.7 ...

Title source: llm
STIX 2.1

Description

A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0050
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
fortinet/fortinac 8.7.0 - 9.4.2
fortinet/fortinac-f 7.2.0
Published May 03, 2023
Tracked Since Feb 18, 2026