CVE-2024-23664
CVE-2024-23664
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.8EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
03 Jun 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:U/RC:C
Affected products
Fortinet · FortiAuthenticatorWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →