CVE-2022-23439
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2022-23439 is a vulnerability affecting multiple Fortinet products, including FortiManager, FortiMail, FortiAnalyzer, FortiVoice, FortiProxy, FortiRecorder, FortiAuthenticator, FortiNDR, FortiWLC, FortiPortal, FortiOS, FortiADC, FortiDDoS, FortiDDoS-F, FortiTester, FortiSOAR, and FortiSwitch. This issue allows an attacker to poison web caches through crafted HTTP requests, where the `Host` header points to an arbitrary webserver. Successful exploitation could result in the delivery of malicious content to unsuspecting users, potentially leading to data theft or unauthorized access. Fortinet urges users to upgrade to the recommended versions to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.