PT-2025-3014 · Fortinet · Fortiproxy+1
Published
2025-01-14
·
Updated
2025-08-08
·
CVE-2024-54021
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions 7.2.0 through 7.6.0
FortiProxy versions 7.2.0 through 7.4.5
Description
The issue is related to an improper neutralization of crlf sequences in http headers, also known as 'http response splitting'. This allows an attacker to execute unauthorized code or commands via a crafted HTTP header. A remote unauthenticated attacker may bypass the file filter via a crafted HTTP header.
Recommendations
For Fortinet FortiOS versions 7.2.0 through 7.6.0, update to a version that fixes the improper neutralization of crlf sequences in http headers.
For FortiProxy versions 7.2.0 through 7.4.5, update to a version that fixes the improper neutralization of crlf sequences in http headers.
As a temporary workaround, consider restricting access to crafted HTTP headers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios
Fortiproxy