CVE-2023-25603
published 2023-11-14CVE-2023-25603: A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an…
critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | 7.1.0 – 7.1.1 | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | 6.3.0 – 6.3.4 | — |
| fortinet | fortiddos-f | 6.4.0 – 6.4.1 | — |
| fortinet | fortinet | — | — |