CVE-2022-27488
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests.
Cross-Site Request Forgery (CSRF) en Fortinet FortiVoiceEnterprise versión 6.4.x, 6.0.x, FortiSwitch versión 7.0.0 a 7.0.4, 6.4.0 a 6.4.10, 6.2.0 a 6.2.7, 6.0.x , FortiMail versión 7.0.0 a 7.0.3, 6.4.0 a 6.4.6, 6.2.x, 6.0.x FortiRecorder versión 6.4.0 a 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR versión 1.xx permite que un atacante remoto no autenticado ejecute comandos en la CLI engañando a un administrador autenticado para que ejecute solicitudes GET maliciosas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-21 CVE Reserved
- 2023-12-13 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/psirt/FG-IR-22-038 | 2024-01-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiai Search vendor "Fortinet" for product "Fortiai" | 1.1.0 Search vendor "Fortinet" for product "Fortiai" and version "1.1.0" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiai Search vendor "Fortinet" for product "Fortiai" | 1.5.3 Search vendor "Fortinet" for product "Fortiai" and version "1.5.3" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 6.0.0 <= 6.0.12 Search vendor "Fortinet" for product "Fortimail" and version " >= 6.0.0 <= 6.0.12" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 6.2.0 <= 6.2.9 Search vendor "Fortinet" for product "Fortimail" and version " >= 6.2.0 <= 6.2.9" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 6.4.0 <= 6.4.6 Search vendor "Fortinet" for product "Fortimail" and version " >= 6.4.0 <= 6.4.6" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortimail Search vendor "Fortinet" for product "Fortimail" | >= 7.0.0 <= 7.0.3 Search vendor "Fortinet" for product "Fortimail" and version " >= 7.0.0 <= 7.0.3" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortindr Search vendor "Fortinet" for product "Fortindr" | >= 7.0.0 <= 7.0.4 Search vendor "Fortinet" for product "Fortindr" and version " >= 7.0.0 <= 7.0.4" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortindr Search vendor "Fortinet" for product "Fortindr" | 7.1.0 Search vendor "Fortinet" for product "Fortindr" and version "7.1.0" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortirecorder Search vendor "Fortinet" for product "Fortirecorder" | >= 2.6.0 <= 2.6.3 Search vendor "Fortinet" for product "Fortirecorder" and version " >= 2.6.0 <= 2.6.3" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortirecorder Search vendor "Fortinet" for product "Fortirecorder" | >= 2.7.0 <= 2.7.7 Search vendor "Fortinet" for product "Fortirecorder" and version " >= 2.7.0 <= 2.7.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortirecorder Search vendor "Fortinet" for product "Fortirecorder" | >= 6.0.0 <= 6.0.11 Search vendor "Fortinet" for product "Fortirecorder" and version " >= 6.0.0 <= 6.0.11" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortirecorder Search vendor "Fortinet" for product "Fortirecorder" | >= 6.4.0 <= 6.4.2 Search vendor "Fortinet" for product "Fortirecorder" and version " >= 6.4.0 <= 6.4.2" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortivoice Search vendor "Fortinet" for product "Fortivoice" | >= 6.0.0 <= 6.0.11 Search vendor "Fortinet" for product "Fortivoice" and version " >= 6.0.0 <= 6.0.11" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortivoice Search vendor "Fortinet" for product "Fortivoice" | >= 6.4.0 <= 6.4.7 Search vendor "Fortinet" for product "Fortivoice" and version " >= 6.4.0 <= 6.4.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | >= 6.0.0 <= 6.0.7 Search vendor "Fortinet" for product "Fortiswitch" and version " >= 6.0.0 <= 6.0.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | >= 6.2.0 <= 6.2.7 Search vendor "Fortinet" for product "Fortiswitch" and version " >= 6.2.0 <= 6.2.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | >= 6.4.0 <= 6.4.10 Search vendor "Fortinet" for product "Fortiswitch" and version " >= 6.4.0 <= 6.4.10" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | >= 7.0.0 <= 7.0.4 Search vendor "Fortinet" for product "Fortiswitch" and version " >= 7.0.0 <= 7.0.4" | - |
Affected
|