CVE-2023-25603
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/11/2023
Last modified:
20/11/2023
Description
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fortinet:fortiadc:7.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:fortiadc:7.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:fortiddos-f:*:*:*:*:*:*:*:* | 6.3.0 (including) | 6.3.4 (including) |
cpe:2.3:a:fortinet:fortiddos-f:6.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:fortiddos-f:6.4.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page