CVE-2016-4066: CSRF
Published Jul 13, 2016
·Updated
Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrators for requests that change the password via unspecified vectors.
Affected Software
1 affected component
Fortinet FortiWeb<=5.5.2
Event History
Jul 13, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4066?
CVE-2016-4066 is classified as a medium severity Cross-site request forgery vulnerability.
2
How do I fix CVE-2016-4066?
To fix CVE-2016-4066, upgrade Fortinet FortiWeb to version 5.5.3 or later.
3
What type of attack does CVE-2016-4066 involve?
CVE-2016-4066 involves a Cross-site request forgery (CSRF) attack that can allow remote attackers to hijack administrator authentication.
4
Which software versions are affected by CVE-2016-4066?
CVE-2016-4066 affects Fortinet FortiWeb versions prior to 5.5.3, including 5.5.2 and earlier.
5
Who is targeted by the CVE-2016-4066 vulnerability?
CVE-2016-4066 specifically targets the authentication of administrators in Fortinet FortiWeb.