MEDIUM · 4.7

CVE-2022-23439

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitr...

Vulnerability Description

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
FortinetFortiadc>= 5.4.0, < 6.2.4
FortinetFortiauthenticator>= 6.3.0, < 6.3.4
FortinetFortiddos>= 5.3.0, < 5.5.2
FortinetFortiddos-F>= 6.1.0, < 6.3.4
FortinetFortimail>= 6.4.0, < 7.0.4
FortinetFortindr>= 1.4.0, < 7.1.1
FortinetFortiproxy>= 2.0.0, < 7.0.5
FortinetFortirecorder>= 6.0.0, < 6.0.11
FortinetFortisoar>= 6.4.0, < 7.3.0
FortinetFortitester>= 3.7.0, < 7.2.2
FortinetFortivoice>= 6.0.0, < 6.4.9
FortinetFortiwlc>= 8.6.0, < 8.6.7
FortinetFortios>= 6.0.0, < 7.0.6
FortinetFortiswitch>= 6.4.0, < 7.0.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-23439?

CVE-2022-23439 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitr...

How severe is CVE-2022-23439?

CVE-2022-23439 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23439?

Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiadc, Fortinet Fortiauthenticator, Fortinet Fortiddos, Fortinet Fortiddos-F, Fortinet Fortimail.