CVE-2022-38381SQL Injection in Fortinet Fortiadc

4 documents4 sources
Severity
9.8CRITICALNVD
CNA5.3
EPSS
0.3%
top 49.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2

Description

An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web Application Firewall (WAF) protection such as the SQL Injection and XSS filters via a malformed HTTP request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortiadc5.0.05.0.4+8
CVEListV5fortinet/fortinet_fortiadcFortiADC 7.0.2, 7.0.1, 7.0.0, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.6, 6.1.5, 6.1.4, 6.1.3, 6.1.2, 6.1.1, 6.1.0, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0, 5.3.7, 5.3.6, 5.3.5, 5.3.4, 5.3.3, 5.3.2, 5.3.1, 5.3.0, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.3, 5.1.2, 5.1.1, 5.1.0, 5.0.4, 5.0.3, 5.0.2, 5.0.1, 5.0.0

🔴Vulnerability Details

2
GHSA
GHSA-4gfr-r6w7-j6c3: An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 52022-11-02
CVEList
CVE-2022-38381: An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 52022-11-02

📋Vendor Advisories

1
Fortinet
An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all version...2022-11-02
CVE-2022-38381 — SQL Injection in Fortinet Fortiadc | cvebase