CVE-2014-3115: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication of administrators via system/config/adminadd and other unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3115?
CVE-2014-3115 is considered a high-severity vulnerability due to its potential to allow remote attackers to hijack administrator sessions.
How do I fix CVE-2014-3115?
To fix CVE-2014-3115, upgrade Fortinet FortiWeb to version 5.2.0 or later.
What types of attacks does CVE-2014-3115 enable?
CVE-2014-3115 enables cross-site request forgery (CSRF) attacks that target the web administration console.
Which versions of Fortinet FortiWeb are affected by CVE-2014-3115?
Versions of Fortinet FortiWeb prior to 5.2.0, including versions from 5.1.0 to 5.1.4, are affected by CVE-2014-3115.
What can be exploited in CVE-2014-3115?
CVE-2014-3115 can be exploited to hijack the authentication of administrators via various console functions.