Skip to content
Threat Feed
low advisory

Fortinet FortiSIEM Open Redirect Vulnerability

A vulnerability in Fortinet FortiSIEM allows a remote, unauthenticated attacker to perform an open redirect, enabling the redirection of users to malicious or untrusted websites.

CVE search metadata

CVE search record: CVE-2024-47576. Severity: low. CVSS: 3.3. EPSS: 0.18%. KEV: no. Product: FortiSIEM (< 4.7.1). Brief: Fortinet FortiSIEM Open Redirect Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-fortinet-fortisiem-open-redirect/

Fortinet has identified a vulnerability in FortiSIEM that exposes users to an open redirect attack. A remote, unauthenticated attacker can exploit this flaw to manipulate URL parameters, causing the application to redirect authenticated or unauthenticated users to a site of the attacker's choosing. This type of vulnerability is frequently leveraged in phishing campaigns, where attackers use trusted domain names to lend credibility to malicious links, increasing the likelihood that users will navigate to credential harvesting or malware delivery sites. Defenders should prioritize auditing web traffic logs for suspicious redirect patterns originating from their FortiSIEM infrastructure.

Impact

Successful exploitation allows attackers to conduct more convincing social engineering and phishing attacks by leveraging the reputation of a legitimate organization's infrastructure. While this vulnerability does not provide direct access to the underlying server, it facilitates the compromise of end-user credentials and increases the success rate of subsequent endpoint exploitation attempts.

Recommendation

Prioritize applying the vendor-supplied security patch to the affected FortiSIEM installation as specified in the official Fortinet security advisory. Monitor web access logs for anomalous redirect targets, specifically identifying URLs that navigate outside of the organization's sanctioned domain space.

Mitigations

Patch FortiSIEM to 4.7.1 or later

short_term IT Operations

CVE-2024-47576