Lucene search

K
nvd[email protected]NVD:CVE-2022-27488
HistoryDec 13, 2023 - 7:15 a.m.

CVE-2022-27488

2023-12-1307:15:10
CWE-352
web.nvd.nist.gov
csrf
remote attack
unauthenticated
command execution
fortinet
fortivoiceenterprise
fortiswitch
fortimail
fortirecorder
fortindr

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

30.2%

A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI viaΒ tricking an authenticated administrator to execute malicious GET requests.

Affected configurations

NVD
Node
fortinetfortiaiMatch1.1.0
OR
fortinetfortiaiMatch1.5.3
OR
fortinetfortimailRange6.0.0–6.0.12
OR
fortinetfortimailRange6.2.0–6.2.9
OR
fortinetfortimailRange6.4.0–6.4.6
OR
fortinetfortimailRange7.0.0–7.0.3
OR
fortinetfortindrRange7.0.0–7.0.4
OR
fortinetfortindrMatch7.1.0
OR
fortinetfortirecorderRange2.6.0–2.6.3
OR
fortinetfortirecorderRange2.7.0–2.7.7
OR
fortinetfortirecorderRange6.0.0–6.0.11
OR
fortinetfortirecorderRange6.4.0–6.4.2
OR
fortinetfortivoiceRange6.0.0–6.0.11
OR
fortinetfortivoiceRange6.4.0–6.4.7
OR
fortinetfortiswitchRange6.0.0–6.0.7
OR
fortinetfortiswitchRange6.2.0–6.2.7
OR
fortinetfortiswitchRange6.4.0–6.4.10
OR
fortinetfortiswitchRange7.0.0–7.0.4

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

30.2%

Related for NVD:CVE-2022-27488