VYPR
Medium severity6.1NVD Advisory· Published Mar 15, 2020· Updated Jun 17, 2026

CVE-2019-6696

CVE-2019-6696

Description

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.

Affected products

5
  • Fortinet/Fortios4 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=5.4.0,<=6.0.8
    • cpe:2.3:o:fortinet:fortios:6.2.0:*:*:*:*:*:*:*
    • cpe:2.3:o:fortinet:fortios:6.2.1:*:*:*:*:*:*:*
    • (no CPE)range: <=6.2.1, <=6.2.0, <=6.0.8, <=5.4.0
  • Fortinet/Fortinetcpe-rescue
    Range: 6.2.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.