CVE Vulnerabilities

CVE-2022-38381

Published: Nov 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web Application Firewall (WAF) protection such as the SQL Injection and XSS filters via a malformed HTTP request.

Affected Software

Name Vendor Start Version End Version
Fortiadc Fortinet 5.0.0 (including) 5.0.4 (including)
Fortiadc Fortinet 5.1.0 (including) 5.1.7 (including)
Fortiadc Fortinet 5.2.0 (including) 5.2.8 (including)
Fortiadc Fortinet 5.3.0 (including) 5.3.7 (including)
Fortiadc Fortinet 5.4.0 (including) 5.4.5 (including)
Fortiadc Fortinet 6.0.0 (including) 6.0.4 (including)
Fortiadc Fortinet 6.1.0 (including) 6.1.6 (including)
Fortiadc Fortinet 6.2.0 (including) 6.2.3 (including)
Fortiadc Fortinet 7.0.0 (including) 7.0.2 (including)

References