A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade olcne-olm-chartUpgrade olcne-metallb-chartUpgrade kubeadmUpgrade olcne-kubevirt-chartUpgrade olcne-grafana-chartUpgrade olcne-rook-chartUpgrade olcne-nginxUpgrade olcne-extra-modulesUpgrade kubeletUpgrade olcne-agentUpgrade olcne-gluster-chartUpgrade olcne-calico-chartUpgrade olcne-multus-chartUpgrade olcneUpgrade olcnectlUpgrade istio-istioctlUpgrade olcne-oci-ccm-chartUpgrade olcne-api-serverUpgrade olcne-prometheus-chartUpgrade kubernetesUpgrade olcne-istio-chartUpgrade istioUpgrade kubectlUpgrade olcne-utils | May 26, 2023 | May 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub