Lucene search

K
cve[email protected]CVE-2013-1414
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1414

2022-10-0316:14:49
CWE-352
web.nvd.nist.gov
40
fortinet
fortios
cross-site request forgery
csrf
vulnerabilities
firewall
remote attackers
authentication

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.4%

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.

Affected configurations

NVD
Node
fortinetfortiosRange4.3.12
OR
fortinetfortiosMatch4.3.10
OR
fortinetfortiosMatch5.0
OR
fortinetfortiosMatch5.0.1
AND
fortinetfortigate-1000cMatch-
OR
fortinetfortigate-100dMatch-
OR
fortinetfortigate-110cMatch-
OR
fortinetfortigate-1240bMatch-
OR
fortinetfortigate-200bMatch-
OR
fortinetfortigate-20cMatch-
OR
fortinetfortigate-300cMatch-
OR
fortinetfortigate-3040bMatch-
OR
fortinetfortigate-310bMatch-
OR
fortinetfortigate-311bMatch-
OR
fortinetfortigate-3140bMatch-
OR
fortinetfortigate-3240cMatch-
OR
fortinetfortigate-3810aMatch-
OR
fortinetfortigate-3950bMatch-
OR
fortinetfortigate-40cMatch-
OR
fortinetfortigate-5001a-swMatch-
OR
fortinetfortigate-5001bMatch-
OR
fortinetfortigate-5020Match-
OR
fortinetfortigate-5060Match-
OR
fortinetfortigate-50bMatch-
OR
fortinetfortigate-5101cMatch-
OR
fortinetfortigate-5140bMatch-
OR
fortinetfortigate-600cMatch-
OR
fortinetfortigate-60cMatch-
OR
fortinetfortigate-620bMatch-
OR
fortinetfortigate-800cMatch-
OR
fortinetfortigate-80cMatch-
OR
fortinetfortigate-voice-80cMatch-
OR
fortinetfortigaterugged-100cMatch-

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.4%