A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.6.0Upgrade to the latest version of FortiAnalyzer | May 26, 2026 | Jan 14, 2025 |
| Fortinet Fortiauthenticator | — | Upgrade FortiAuthenticator to 6.3.4Upgrade FortiAuthenticator to 6.4.2Upgrade to the latest version of FortiAuthenticator | Aug 5, 2026 | Jan 14, 2025 |
| Fortinet Fortimanager | — | Upgrade to the latest version of FortiManagerUpgrade FortiManager to 7.6.0 | May 25, 2026 | Jan 14, 2025 |
| Fortios | — | Upgrade FortiOS to 7.2.5Upgrade FortiOS to 7.0.12Upgrade FortiOS to 7.2.1Upgrade to the latest version of FortiOSUpgrade FortiOS to 6.4.13Upgrade FortiOS to 7.4.0Upgrade FortiOS to 7.0.6 | Feb 14, 2025 | Jan 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub