CVE-2019-6696: Input Validation
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6696?
CVE-2019-6696 has been classified with a medium severity level due to its potential for URL redirection attacks.
How do I fix CVE-2019-6696?
To remediate CVE-2019-6696, upgrade FortiOS to version 6.2.2 or later, or apply the relevant patches provided by Fortinet.
What versions of FortiOS are affected by CVE-2019-6696?
CVE-2019-6696 affects FortiOS versions 6.2.0, 6.2.1, and versions below 6.0.8 until 5.4.0.
What kind of attack can be executed using CVE-2019-6696?
CVE-2019-6696 allows attackers to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.
Is there a workaround for CVE-2019-6696 if I cannot upgrade?
No official workarounds are provided for CVE-2019-6696; it is recommended to upgrade FortiOS to resolve the vulnerability.