PT-2019-5812 · Fortinet · Fortios

Published

2019-05-17

·

Updated

2020-01-03

·

CVE-2018-13384

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions prior to 6.0.5
Description A Host Header Redirection issue allows a remote attacker to potentially poison HTTP cache and redirect SSL VPN web portal users to arbitrary web domains. This is achieved by submitting specially crafted HTTP requests to the SSL-VPN web portal, which may respond with a redirection to attacker-specified websites. If a web proxy's cache is poisoned with this redirection, users may be directed to the attacker's specified websites when trying to access the SSL-VPN web portal.
Recommendations For versions prior to 6.0.5, update to version 6.0.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSL-VPN web portal to minimize the risk of exploitation. Additionally, avoid using web proxies that may have cached the malicious redirection until the issue is resolved.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03019
CVE-2018-13384

Affected Products

Fortios