CVE Vulnerabilities

CVE-2022-38381

Published: Nov 02, 2022 | Modified: Nov 04, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web Application Firewall (WAF) protection such as the SQL Injection and XSS filters via a malformed HTTP request.

Affected Software

Name Vendor Start Version End Version
Fortiadc Fortinet 5.0.0 (including) 5.0.4 (including)
Fortiadc Fortinet 5.1.0 (including) 5.1.7 (including)
Fortiadc Fortinet 5.2.0 (including) 5.2.8 (including)
Fortiadc Fortinet 5.3.0 (including) 5.3.7 (including)
Fortiadc Fortinet 5.4.0 (including) 5.4.5 (including)
Fortiadc Fortinet 6.0.0 (including) 6.0.4 (including)
Fortiadc Fortinet 6.1.0 (including) 6.1.6 (including)
Fortiadc Fortinet 6.2.0 (including) 6.2.3 (including)
Fortiadc Fortinet 7.0.0 (including) 7.0.2 (including)

References