This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:MISC:FORTIGATE-CSRF
|
Severity |
Minor
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Fortigate Firewalls Cross-Site Request Forgery
|
Release Date |
2013/07/23
|
Update Number |
2284
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Fortigate Firewalls Cross-Site Request Forgery
This signature detects attempts to exploit a known vulnerability against Fortigate Firewalls. A successful attack can lead to cross-site request forgery attacks and unauthorized session hijacks.
Extended Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
Affected Products
- Fortinet fortigate-1000c -
- Fortinet fortigate-100d -
- Fortinet fortigate-110c -
- Fortinet fortigate-1240b -
- Fortinet fortigate-200b -
- Fortinet fortigate-20c -
- Fortinet fortigate-300c -
- Fortinet fortigate-3040b -
- Fortinet fortigate-310b -
- Fortinet fortigate-311b -
- Fortinet fortigate-3140b -
- Fortinet fortigate-3240c -
- Fortinet fortigate-3810a -
- Fortinet fortigate-3950b -
- Fortinet fortigate-40c -
- Fortinet fortigate-5001a-sw -
- Fortinet fortigate-5001b -
- Fortinet fortigate-5020 -
- Fortinet fortigate-5060 -
- Fortinet fortigate-50b -
- Fortinet fortigate-5101c -
- Fortinet fortigate-5140b -
- Fortinet fortigate-600c -
- Fortinet fortigate-60c -
- Fortinet fortigate-620b -
- Fortinet fortigate-800c -
- Fortinet fortigate-80c -
- Fortinet fortigaterugged-100c -
- Fortinet fortigate-voice-80c -
- Fortinet fortios 4.3.10
- Fortinet fortios 4.3.12
- Fortinet fortios 5.0
- Fortinet fortios 5.0.1
References