Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fortinet
Subscribe
|
Fortigate-1000c
Subscribe
Fortigate-100d
Subscribe
Fortigate-110c
Subscribe
Fortigate-1240b
Subscribe
Fortigate-200b
Subscribe
Fortigate-20c
Subscribe
Fortigate-300c
Subscribe
Fortigate-3040b
Subscribe
Fortigate-310b
Subscribe
Fortigate-311b
Subscribe
Fortigate-3140b
Subscribe
Fortigate-3240c
Subscribe
Fortigate-3810a
Subscribe
Fortigate-3950b
Subscribe
Fortigate-40c
Subscribe
Fortigate-5001a-sw
Subscribe
Fortigate-5001b
Subscribe
Fortigate-5020
Subscribe
Fortigate-5060
Subscribe
Fortigate-50b
Subscribe
Fortigate-5101c
Subscribe
Fortigate-5140b
Subscribe
Fortigate-600c
Subscribe
Fortigate-60c
Subscribe
Fortigate-620b
Subscribe
Fortigate-800c
Subscribe
Fortigate-80c
Subscribe
Fortigate-voice-80c
Subscribe
Fortigaterugged-100c
Subscribe
Fortios
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-1452 | Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://www.exploit-db.com/exploits/26528/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:16:50.095Z
Reserved: 2013-01-24T00:00:00Z
Link: CVE-2013-1414
No data.
Status : Deferred
Published: 2013-07-08T17:55:02.783
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-1414
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD