5.1
CVSSv2

CVE-2013-1414

Published: 08/07/2013 Updated: 08/07/2013
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices prior to 4.3.13 and 5.x prior to 5.0.2 allow remote malicious users to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 5.0.1

fortinet fortios 5.0

fortinet fortios

fortinet fortios 4.3.10

fortinet fortigate-3040b -

fortinet fortigate-3240c -

fortinet fortigate-5001b -

fortinet fortigate-80c -

fortinet fortigate-40c -

fortinet fortigate-20c -

fortinet fortigate-110c -

fortinet fortigate-voice-80c -

fortinet fortigate-1240b -

fortinet fortigate-300c -

fortinet fortigate-5020 -

fortinet fortigate-3950b -

fortinet fortigate-311b -

fortinet fortigate-310b -

fortinet fortigate-800c -

fortinet fortigate-5001a-sw -

fortinet fortigate-5101c -

fortinet fortigate-600c -

fortinet fortigate-200b -

fortinet fortigate-100d -

fortinet fortigate-5060 -

fortinet fortigate-3810a -

fortinet fortigate-60c -

fortinet fortigate-50b -

fortinet fortigate-620b -

fortinet fortigaterugged-100c -

fortinet fortigate-1000c -

fortinet fortigate-5140b -

fortinet fortigate-3140b -

Exploits

Vulnerability ID: CVE-2013-1414 Vulnerability Type: CSRF (Cross-Site Request Forgery) Product: All Fortigate Firewalls Vendor: Fortinet wwwfortinetcom Vulnerable Version: < 4313 & < 502 Description ========== Because many functions are not protected by CSRF-Tokens, it's possible (under certain conditions) to modify System ...
Fortigate Firewall versions prior to 4313 and 502 suffer from multiple cross site request forgery vulnerabilities ...