CVE-2022-27488: CSRF
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27488?
CVE-2022-27488 is rated as a critical vulnerability due to its potential impact on affected systems.
How do I fix CVE-2022-27488?
To mitigate CVE-2022-27488, update Fortinet FortiVoice, FortiMail, FortiSwitch, or FortiRecorder to the latest patched versions.
Which versions are affected by CVE-2022-27488?
CVE-2022-27488 affects multiple versions of Fortinet FortiVoice, FortiMail, FortiSwitch, and FortiRecorder across several release iterations.
Is CVE-2022-27488 a cross-site request forgery vulnerability?
Yes, CVE-2022-27488 is identified as a cross-site request forgery (CSRF) vulnerability.
What types of products are affected by CVE-2022-27488?
CVE-2022-27488 affects various Fortinet products including FortiVoice, FortiMail, FortiSwitch, and FortiRecorder.