// For flags

CVE-2013-6826

Fortinet FortiAnalyzer - Cross-Site Request Forgery

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

cgi-bin/module/sysmanager/admin/SYSAdminUserDialog en Fortinet FortiAnalyzer anterior a la versión 5.0.5 no valida adecuadamente el parámetro csrf_token, lo que permite a atacantes remotos realizar ataques de CSRF.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-10-12 First Exploit
  • 2013-11-19 CVE Reserved
  • 2013-11-19 CVE Published
  • 2024-09-16 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Fortinet
Search vendor "Fortinet"
Fortianalyzer Firmware
Search vendor "Fortinet" for product "Fortianalyzer Firmware"
<= 5.0.4
Search vendor "Fortinet" for product "Fortianalyzer Firmware" and version " <= 5.0.4"
-
Affected
in Fortinet
Search vendor "Fortinet"
Fortianalyzer-1000d
Search vendor "Fortinet" for product "Fortianalyzer-1000d"
--
Affected
Fortinet
Search vendor "Fortinet"
Fortianalyzer Firmware
Search vendor "Fortinet" for product "Fortianalyzer Firmware"
<= 5.0.4
Search vendor "Fortinet" for product "Fortianalyzer Firmware" and version " <= 5.0.4"
-
Affected
in Fortinet
Search vendor "Fortinet"
Fortianalyzer-2000b
Search vendor "Fortinet" for product "Fortianalyzer-2000b"
--
Affected
Fortinet
Search vendor "Fortinet"
Fortianalyzer Firmware
Search vendor "Fortinet" for product "Fortianalyzer Firmware"
<= 5.0.4
Search vendor "Fortinet" for product "Fortianalyzer Firmware" and version " <= 5.0.4"
-
Affected
in Fortinet
Search vendor "Fortinet"
Fortianalyzer-200d
Search vendor "Fortinet" for product "Fortianalyzer-200d"
--
Affected
Fortinet
Search vendor "Fortinet"
Fortianalyzer Firmware
Search vendor "Fortinet" for product "Fortianalyzer Firmware"
<= 5.0.4
Search vendor "Fortinet" for product "Fortianalyzer Firmware" and version " <= 5.0.4"
-
Affected
in Fortinet
Search vendor "Fortinet"
Fortianalyzer-3000d
Search vendor "Fortinet" for product "Fortianalyzer-3000d"
--
Affected
Fortinet
Search vendor "Fortinet"
Fortianalyzer Firmware
Search vendor "Fortinet" for product "Fortianalyzer Firmware"
<= 5.0.4
Search vendor "Fortinet" for product "Fortianalyzer Firmware" and version " <= 5.0.4"
-
Affected
in Fortinet
Search vendor "Fortinet"
Fortianalyzer-300d
Search vendor "Fortinet" for product "Fortianalyzer-300d"
--
Affected
Fortinet
Search vendor "Fortinet"
Fortianalyzer Firmware
Search vendor "Fortinet" for product "Fortianalyzer Firmware"
<= 5.0.4
Search vendor "Fortinet" for product "Fortianalyzer Firmware" and version " <= 5.0.4"
-
Affected
in Fortinet
Search vendor "Fortinet"
Fortianalyzer-4000b
Search vendor "Fortinet" for product "Fortianalyzer-4000b"
--
Affected