Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.

Project Subscriptions

Vendors Products
Fortinet Subscribe
Fortigate-1000c Subscribe
Fortigate-100d Subscribe
Fortigate-110c Subscribe
Fortigate-1240b Subscribe
Fortigate-200b Subscribe
Fortigate-20c Subscribe
Fortigate-300c Subscribe
Fortigate-3040b Subscribe
Fortigate-310b Subscribe
Fortigate-311b Subscribe
Fortigate-3140b Subscribe
Fortigate-3240c Subscribe
Fortigate-3810a Subscribe
Fortigate-3950b Subscribe
Fortigate-40c Subscribe
Fortigate-5001a-sw Subscribe
Fortigate-5001b Subscribe
Fortigate-5020 Subscribe
Fortigate-5060 Subscribe
Fortigate-50b Subscribe
Fortigate-5101c Subscribe
Fortigate-5140b Subscribe
Fortigate-600c Subscribe
Fortigate-60c Subscribe
Fortigate-620b Subscribe
Fortigate-800c Subscribe
Fortigate-80c Subscribe
Fortigate-voice-80c Subscribe
Fortigaterugged-100c Subscribe
Fortios Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2013-1452 Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T20:16:50.095Z

Reserved: 2013-01-24T00:00:00Z

Link: CVE-2013-1414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-07-08T17:55:02.783

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-1414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses