Fortinet FortiAnalyzer and FortiManager CVE-2018-1355 Open Redirect Vulnerability
BID:104546
CVE-2018-1355 |Info
Fortinet FortiAnalyzer and FortiManager CVE-2018-1355 Open Redirect Vulnerability
| Bugtraq ID: | 104546 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1355 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2018 12:00AM |
| Updated: | Jun 22 2018 12:00AM |
| Credit: | Donato Onofri, Luca Napolitano and Francesca Perrone of Business Integration Partners S.p.A. |
| Vulnerable: |
Fortinet FortiManager 6.0 Fortinet FortiManager 5.4.4 Fortinet FortiManager 5.4.2 Fortinet FortiManager 5.4.1 Fortinet FortiManager 5.4 Fortinet FortiManager 5.2.8 Fortinet FortiManager 5.2.7 Fortinet FortiManager 5.2.6 Fortinet FortiManager 5.2.5 Fortinet FortiManager 5.2.2 Fortinet FortiManager 5.2.1 Fortinet FortiManager 5.2 Fortinet FortiManager 5.0.12 Fortinet FortiManager 5.0.11 Fortinet FortiManager 5.0.10 Fortinet FortiManager 5.0.9 Fortinet FortiManager 5.0.8 Fortinet FortiManager 5.0.7 Fortinet FortiManager 5.0.6 Fortinet FortiManager 5.0.5 Fortinet FortiManager 5.0.4 Fortinet FortiManager 5.0.3 Fortinet FortiManager 5.0.2 Fortinet FortiManager 5.0.1 Fortinet FortiManager 2.80 Fortinet FortiManager 5.2.4 Fortinet FortiManager 5.2.3 Fortinet FortiManager 5.0 Fortinet FortiManager 4.3 Fortinet FortiManager 3.0 Fortinet FortiAnalyzer 6.0 Fortinet FortiAnalyzer 5.4.1 Fortinet FortiAnalyzer 5.4 Fortinet FortiAnalyzer 5.2.6 Fortinet FortiAnalyzer 5.2.5 Fortinet FortiAnalyzer 5.2.3 Fortinet FortiAnalyzer 5.2.2 Fortinet FortiAnalyzer 5.2.1 Fortinet FortiAnalyzer 5.2 Fortinet FortiAnalyzer 5.0.13 Fortinet FortiAnalyzer 5.0.12 Fortinet FortiAnalyzer 5.0.11 Fortinet FortiAnalyzer 5.0.10 Fortinet FortiAnalyzer 5.0.9 Fortinet FortiAnalyzer 5.0.7 Fortinet FortiAnalyzer 5.0.5 Fortinet FortiAnalyzer 5.0.4 Fortinet FortiAnalyzer 5.0 Fortinet FortiAnalyzer 4.3.7 Fortinet FortiAnalyzer 4.3.6 Fortinet FortiAnalyzer 3.0 |
| Not Vulnerable: |
Fortinet FortiManager 6.0.1 Fortinet FortiAnalyzer 6.0.1 |
Discussion
Fortinet FortiAnalyzer and FortiManager CVE-2018-1355 Open Redirect Vulnerability
Fortinet FortiAnalyzer and FortiManager are prone to an open-redirect vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following products and versions are vulnerable:
FortiAnalyzer 6.0.0 and prior
FortiManager 6.0.0 and prior
Fortinet FortiAnalyzer and FortiManager are prone to an open-redirect vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following products and versions are vulnerable:
FortiAnalyzer 6.0.0 and prior
FortiManager 6.0.0 and prior
Exploit / POC
Fortinet FortiAnalyzer and FortiManager CVE-2018-1355 Open Redirect Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Fortinet FortiAnalyzer and FortiManager CVE-2018-1355 Open Redirect Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.