CVE-2022-23439

EUVD-2022-28514
A externally controlled reference to a resource in another sphere vulnerability in Fortinet  allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
fortinetCNA
4.1 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
fortinetfortiadc
5.4.0 ≤
𝑥
< 6.2.4
fortinetfortiauthenticator
6.3.0 ≤
𝑥
< 6.3.4
fortinetfortiauthenticator
6.4.0 ≤
𝑥
< 6.4.2
fortinetfortiddos
5.3.0 ≤
𝑥
< 5.5.2
fortinetfortiddos-f
6.1.0 ≤
𝑥
< 6.3.4
fortinetfortimail
6.4.0 ≤
𝑥
< 7.0.4
fortinetfortindr
1.4.0 ≤
𝑥
< 7.1.1
fortinetfortindr
7.2.0
fortinetfortiproxy
2.0.0 ≤
𝑥
< 7.0.5
fortinetfortiproxy
7.2.0 ≤
𝑥
< 7.4.0
fortinetfortirecorder
6.0.0 ≤
𝑥
< 6.0.11
fortinetfortirecorder
6.4.0 ≤
𝑥
< 6.4.3
fortinetfortisoar
6.4.0 ≤
𝑥
< 7.3.0
fortinetfortitester
3.7.0 ≤
𝑥
< 7.2.2
fortinetfortivoice
6.0.0 ≤
𝑥
< 6.4.9
fortinetfortiwlc
8.6.0 ≤
𝑥
< 8.6.7
fortinetfortios
6.0.0 ≤
𝑥
< 7.0.6
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.5
fortinetfortiswitch
6.4.0 ≤
𝑥
< 7.0.5
𝑥
= Vulnerable software versions