ZeroHour

CVE-2019-6696

CVSS 3.1
6.1 medium
EPSS
<1%p51
Published
()
Modified
Description

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.

Vendors
fortinet
Products
fortios
Weakness
CWE-20, CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.