CVE-2024-23664

MEDIUM

FortiAuthenticator 6.4.0-6.4.9, 6.5.0-6.5.3, 6.6.0 - Open Redirect via Crafted URL

Title source: llm
STIX 2.1

Description

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0033
EPSS Percentile 56.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
fortinet/fortiauthenticator 6.6.0
fortinet/fortiauthenticator 6.4.0 - 6.5.4
Published Jun 03, 2024
Tracked Since Feb 18, 2026