CVE-2022-23439

CWE-6104 documents4 sources
Severity
6.1MEDIUM
EPSS
0.2%
top 56.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22

Description

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.7

Affected Packages31 packages

CVEListV5fortinet/fortios6.4.06.4.*+5
NVDfortinet/fortios6.0.07.0.6+1
NVDfortinet/fortiadc5.4.06.2.4
NVDfortinet/fortindr1.4.07.1.1+1
NVDfortinet/fortiwlc8.6.08.6.7

🔴Vulnerability Details

2
GHSA
GHSA-xw2g-vg83-c99r: A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 72025-01-22
CVEList
CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requ2025-01-22

📋Vendor Advisories

1
Fortinet
`Host` header injection2025-01-22
CVE-2022-23439 (MEDIUM CVSS 6.1) | A externally controlled reference t | cvebase.io