QID 43985
Date Published: 2023-02-22
QID 43985: FortiOS Header Injection In Proxy Vulnerability (FG-IR-22-362)
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an authenticated and remote attacker to inject arbitrary headers.
Affected Versions:
FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS 6.4 all versions
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-362
Vendor References
- FG-IR-22-362 -
www.fortiguard.com/psirt/FG-IR-22-362
CVEs related to QID 43985
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-362 |
|