PT-2025-3014 · Fortinet · Fortiproxy+1

Published

2025-01-14

·

Updated

2025-08-08

·

CVE-2024-54021

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 7.2.0 through 7.6.0 FortiProxy versions 7.2.0 through 7.4.5
Description The issue is related to an improper neutralization of crlf sequences in http headers, also known as 'http response splitting'. This allows an attacker to execute unauthorized code or commands via a crafted HTTP header. A remote unauthenticated attacker may bypass the file filter via a crafted HTTP header.
Recommendations For Fortinet FortiOS versions 7.2.0 through 7.6.0, update to a version that fixes the improper neutralization of crlf sequences in http headers. For FortiProxy versions 7.2.0 through 7.4.5, update to a version that fixes the improper neutralization of crlf sequences in http headers. As a temporary workaround, consider restricting access to crafted HTTP headers to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-04289
CVE-2024-54021

Affected Products

Fortios
Fortiproxy