Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23439


A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before version 7.0.4, FortiRecorder version 6.4.0 through 6.4.2 and before 6.0.10, FortiAuthenticator version 6.4.0 through 6.4.1 and before 6.3.3, FortiNDR version 7.2.0 before 7.1.0, FortiWLC before version 8.6.4, FortiPortal before version 6.0.9, FortiOS version 7.2.0 and before 7.0.5, FortiADC version 7.0.0 through 7.0.1 and before 6.2.3 , FortiDDoS before version 5.5.1, FortiDDoS-F before version 6.3.3, FortiTester before version 7.2.1, FortiSOAR before version 7.2.2 and FortiSwitch before version 6.3.3 allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver


Published

2025-01-22T10:15:07.737

Last Modified

2025-02-12T13:39:42.107

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-610

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiadc < 6.2.4 Yes
Application fortinet fortiauthenticator < 6.3.4 Yes
Application fortinet fortiauthenticator < 6.4.2 Yes
Application fortinet fortiddos < 5.5.2 Yes
Application fortinet fortiddos-f < 6.3.4 Yes
Application fortinet fortimail < 7.0.4 Yes
Application fortinet fortindr < 7.1.1 Yes
Application fortinet fortindr 7.2.0 Yes
Application fortinet fortiproxy < 7.0.5 Yes
Application fortinet fortiproxy < 7.4.0 Yes
Application fortinet fortirecorder < 6.0.11 Yes
Application fortinet fortirecorder < 6.4.3 Yes
Application fortinet fortisoar < 7.3.0 Yes
Application fortinet fortitester < 7.2.2 Yes
Application fortinet fortivoice < 6.4.9 Yes
Application fortinet fortiwlc < 8.6.7 Yes
Operating System fortinet fortios < 7.0.6 Yes
Operating System fortinet fortios < 7.2.5 Yes
Operating System fortinet fortiswitch < 7.0.5 Yes

References