CVE-2023-25603
published 2023-11-14CVE-2023-25603: A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an…
PriorityP347critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.40%
31.6th percentile
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | 7.1.0 – 7.1.1 | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | 6.3.0 – 6.3.4 | — |
| fortinet | fortiddos-f | 6.4.0 – 6.4.1 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8x2v-m87x-jx78: A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7
ghsa_unreviewed·2023-11-14
CVE-2023-25603 [MEDIUM] CWE-942 GHSA-8x2v-m87x-jx78: A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
Fortinet
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6...
vendor_fortinet·2023-11-14·CVSS 5.4
CVE-2023-25603 [MEDIUM] CWE-942 A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6...
FG-IR-22-518: A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6...
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
CVEs: CVE-2023-25603
CWEs: CWE-942
CVSS: 5.4 (medium)
Affected products: FortiADC, FortiDDoS, FortiDdos-f, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-14
Published