CVE-2022-23439
mediumCVSS v3 Base Score
4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.2%
Exploitation probability in 30 days
Top 57% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Confidentiality
Low
Integrity
Low
Availability
None
Vulnerability Report
Generated by CyberWatcher
Description
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
CWE
CWE-610Affected Products
fortinet fortiadcfortinet fortiauthenticatorfortinet fortiddosfortinet fortiddos-ffortinet fortimailfortinet fortindrfortinet fortiproxyfortinet fortirecorderfortinet fortisoarfortinet fortitester