ZeroHour

CVE-2022-23439

CVSS 3.1
6.1 medium
EPSS
<1%p38
Published
()
Modified
Description

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

Vendors
fortinet
Products
fortiadc, fortiauthenticator, fortiddos, fortiddos-f, fortimail, fortindr, fortiproxy, fortirecorder, fortisoar, fortitester, fortivoice, fortiwlc
Weakness
CWE-610
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.