CVE-2022-23439: `Host` header injection

Published Jan 14, 2025
·
Updated

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the Host header points to an arbitrary webserver

Other sources

An externally controlled reference to a resource in another sphere vulnerability [CWE-610] in multiple products may allow an unauthenticated attacker to poison web caches between the device and the attacker via crafted HTTP requests, where the Host header points to an arbitrary webserver.

FortiGuard

Affected Software

36 affected components
Fortinet FortiManager<7.4.3
Fortinet FortiMail<7.0.3
Fortinet FortiAnalyzer<7.4.3
Fortinet FortiVoice>=7.0.0<7.0.1, <6.4.8
Fortinet FortiProxy<7.0.4
Fortinet FortiRecorder>=6.4.0<6.4.2, <6.0.10
Fortinet FortiAuthenticator>=6.4.0<6.4.1, <6.3.3
Fortinet FortiNDR<7.1.0
Fortinet FortiWLC<8.6.4
Fortinet FortiPortal<6.0.9
Fortinet FortiOS<7.0.5, <7.2.0
Fortinet FortiADC>=7.0.0<7.0.1, <6.2.3
Fortinet FortiDDoS<5.5.1
Fortinet FortiDDoS-F<6.3.3
Fortinet FortiTester<7.2.1
Fortinet FortiSOAR<7.2.2
Fortinet FortiSwitch<6.3.3
Fortinet FortiADC>=5.4.0<6.2.4
Fortinet FortiAuthenticator>=6.3.0<6.3.4
Fortinet FortiAuthenticator>=6.4.0<6.4.2
Fortinet FortiDDoS>=5.3.0<5.5.2
Fortinet FortiDDoS-F>=6.1.0<6.3.4
Fortinet FortiMail>=6.4.0<7.0.4
Fortinet FortiNDR>=1.4.0<7.1.1
Fortinet FortiNDR=7.2.0
Fortinet FortiProxy>=2.0.0<7.0.5
Fortinet FortiProxy>=7.2.0<7.4.0
Fortinet FortiRecorder>=6.0.0<6.0.11
Fortinet FortiRecorder>=6.4.0<6.4.3
Fortinet FortiSOAR>=6.4.0<7.3.0
Fortinet FortiTester>=3.7.0<7.2.2
Fortinet FortiVoice>=6.0.0<6.4.9
Fortinet FortiWLC>=8.6.0<8.6.7
Fortinet FortiOS>=6.0.0<7.0.6
Fortinet FortiOS>=7.2.0<7.2.5
Fortinet FortiSwitch>=6.4.0<7.0.5

Remediation

Information

FortiOS Administrative Interface Upgrade to FortiOS version 7.0.6 and above, Upgrade to FortiOS version 7.2.1 and above. AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`: config system global     set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection" SSLVPN interface Upgrade to FortiOS version 7.4.0 or above Upgrade to FortiOS version 7.2.5 or above AND Set the `server-hostname` property to the device hostname, which will disable `Host redirection` for SSL VPN: config vpn ssl settings                  set server-hostname Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection. Webfilter interface (port 8008) Upgrade to FortiOS version 7.4.0 or above Upgrade to FortiOS version 7.2.5 or above Upgrade to FortiOS version 7.0.12 or above Upgrade to FortiOS version 6.4.13 or above FortiProxy Administrative Interface Upgrade to FortiProxy version 7.0.5 and above AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`: config system global     set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection" SSLVPN interface Upgrade to FortiProxy version 7.4.0 or above AND Set the `server-hostname` property to the device hostname, which will disable `Host redirection` for SSL VPN: config vpn ssl settings                  set server-hostname Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection. WebFilter interface (port 8008) Upgrade to FortiProxy version 7.4.0 or above Upgrade to FortiRecorder version 7.0.0 or above Upgrade to FortiRecorder version 6.4.3 or above Upgrade to FortiRecorder version 6.0.11 or above Upgrade to FortiNDR version 7.4.0 or above FortiAnalyzer & FortiManager Upgrade to version 7.6.0 or above Upgrade to version 7.4.4 or above Set the `admin-host` property to the device hostname, which will disable `Host redirection` for administrative interface. config system global set admin-host end FortiNDR Upgrade to FortiNDR version 7.2.1 or above Upgrade to FortiNDR version 7.1.1 or above AND Set the `https-redirect-host` property to the device hostname, which will disable `Host redirection`: config system global     set https-redirect-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection" end FortiADC Upgrade to FortiADC version 7.1.0 or above Upgrade to FortiADC version 7.0.2 or above Upgrade to FortiADC version 6.2.4 or above AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`:   config system global     set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection" FortiDDOS-F Upgrade to FortiDDoS-F version 6.4.0 or above Upgrade to FortiDDoS-F version 6.3.4 or above AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`:   config system global     set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection" Upgrade to FortiSwitch version 7.2.0 or above Upgrade to FortiSwitch version 7.0.5 or above Upgrade to FortiSwitch version 6.4.11 or above Upgrade to FortiVoice version 7.0.2 or above Upgrade to FortiVoice version 6.4.9 or above Upgrade to FortiMail version 7.2.0 or above Upgrade to FortiMail version 7.0.4 or above Upgrade to FortiWLC version 8.6.7 or above Upgrade to FortiAuthenticator version 6.4.2 or above Upgrade to FortiAuthenticator version 6.3.4 or above Upgrade to FortiDDoS version 5.6.0 or above Upgrade to FortiDDoS version 5.5.2 or above Upgrade to FortiSOAR version 7.3.0 or above Upgrade to FortiTester version 7.3.0 or above Upgrade to FortiTester version 7.2.2 or above

Event History

Jan 14, 2025
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Jan 22, 2025
CVE Published
via MITRE·09:10 AM
Data Sourced
via MITRE·09:10 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 13, 2026
Advisory Published
via FortiGuard·04:53 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-23439?

CVE-2022-23439 is classified with a medium severity level, indicating a potential risk to affected systems.

2

How can I mitigate CVE-2022-23439?

To remediate CVE-2022-23439, upgrade affected Fortinet products to versions released after 7.4.3 for FortiManager and FortiAnalyzer, 7.0.3 for FortiMail, and other respective versions for other products.

3

Which Fortinet products are affected by CVE-2022-23439?

CVE-2022-23439 affects FortiManager, FortiMail, FortiAnalyzer, FortiVoice, FortiProxy, FortiRecorder, among others.

4

Is there a known exploit for CVE-2022-23439?

There is currently no public information regarding known exploits specifically targeting CVE-2022-23439.

5

What types of vulnerabilities does CVE-2022-23439 represent?

CVE-2022-23439 represents an externally controlled reference to a resource in another sphere, which can lead to unauthorized access in affected Fortinet systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203