CVE-2013-1414: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1414?
CVE-2013-1414 has a critical severity rating due to its ability to allow unauthorized changes to FortiGate firewall settings.
How do I fix CVE-2013-1414?
To fix CVE-2013-1414, upgrade Fortinet FortiOS to version 4.3.13 or later, or to any 5.x version higher than 5.0.2.
What are the potential impacts of CVE-2013-1414?
The potential impacts of CVE-2013-1414 include unauthorized access to administrative functions, allowing attackers to modify settings, policies, or restart the device.
Which devices are affected by CVE-2013-1414?
CVE-2013-1414 affects various Fortinet FortiGate firewall devices running FortiOS versions prior to 4.3.13 and 5.x versions before 5.0.2.
Can CVE-2013-1414 be exploited remotely?
Yes, CVE-2013-1414 can be exploited remotely, allowing attackers to hijack the authentication of administrators.