Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-27488


A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests.


Published

2023-12-13T07:15:10.910

Last Modified

2024-11-21T06:55:49.453

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-352
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiai 1.1.0 Yes
Application fortinet fortiai 1.5.3 Yes
Application fortinet fortimail ≤ 6.0.12 Yes
Application fortinet fortimail ≤ 6.2.9 Yes
Application fortinet fortimail ≤ 6.4.6 Yes
Application fortinet fortimail ≤ 7.0.3 Yes
Application fortinet fortindr ≤ 7.0.4 Yes
Application fortinet fortindr 7.1.0 Yes
Application fortinet fortirecorder ≤ 2.6.3 Yes
Application fortinet fortirecorder ≤ 2.7.7 Yes
Application fortinet fortirecorder ≤ 6.0.11 Yes
Application fortinet fortirecorder ≤ 6.4.2 Yes
Application fortinet fortivoice ≤ 6.0.11 Yes
Application fortinet fortivoice ≤ 6.4.7 Yes
Operating System fortinet fortiswitch ≤ 6.0.7 Yes
Operating System fortinet fortiswitch ≤ 6.2.7 Yes
Operating System fortinet fortiswitch ≤ 6.4.10 Yes
Operating System fortinet fortiswitch ≤ 7.0.4 Yes

References