CVE-2024-54021

Severity CVSS v4.0:
Pending analysis
Type:
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Publication date:
14/01/2025
Last modified:
03/02/2025

Description

An improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 allows attacker to execute unauthorized code or commands via crafted HTTP header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.12 (excluding)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.6 (excluding)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.9 (excluding)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.5 (excluding)
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools