First published: Mon Jul 08 2013(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | <=4.3.12 | |
Fortinet FortiOS | =4.3.10 | |
Fortinet FortiOS | =5.0 | |
Fortinet FortiOS | =5.0.1 | |
Fortinet Fortigate-1000c | ||
Fortinet Fortigate-100d | ||
Fortinet Fortigate-110c | ||
Fortinet Fortigate-1240b | ||
Fortinet Fortigate-200b | ||
Fortinet Fortigate-20c | ||
Fortinet Fortigate-300c | ||
Fortinet Fortigate-3040b | ||
Fortinet Fortigate-310b | ||
Fortinet Fortigate-311b | ||
Fortinet Fortigate-3140b | ||
Fortinet Fortigate-3240c | ||
Fortinet Fortigate-3810a | ||
Fortinet Fortigate-3950b | ||
Fortinet Fortigate-40c | ||
Fortinet Fortigate-5001a-sw | ||
Fortinet Fortigate-5001b | ||
Fortinet Fortigate-5020 | ||
Fortinet Fortigate-5060 | ||
Fortinet Fortigate-50b | ||
Fortinet Fortigate-5101c | ||
Fortinet Fortigate-5140b | ||
Fortinet Fortigate-600c | ||
Fortinet Fortigate-60c | ||
Fortinet Fortigate-620b | ||
Fortinet Fortigate-800c | ||
Fortinet Fortigate-80c | ||
Fortinet Fortigate-voice-80c | ||
Fortinet Fortigaterugged-100c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.