Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:MISC:FORTIGATE-CSRF

Severity

Medium

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Fortigate Firewalls Cross-Site Request Forgery

Release Date

2013/07/23

Update Number

2284

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Fortigate Firewalls Cross-Site Request Forgery


This signature detects attempts to exploit a known vulnerability against Fortigate Firewalls. A successful attack can lead to cross-site request forgery attacks and unauthorized session hijacks.

Extended Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.

Affected Products

  • fortinet fortigate-1000c -
  • fortinet fortigate-100d -
  • fortinet fortigate-110c -
  • fortinet fortigate-1240b -
  • fortinet fortigate-200b -
  • fortinet fortigate-20c -
  • fortinet fortigate-300c -
  • fortinet fortigate-3040b -
  • fortinet fortigate-310b -
  • fortinet fortigate-311b -
  • fortinet fortigate-3140b -
  • fortinet fortigate-3240c -
  • fortinet fortigate-3810a -
  • fortinet fortigate-3950b -
  • fortinet fortigate-40c -
  • fortinet fortigate-5001a-sw -
  • fortinet fortigate-5001b -
  • fortinet fortigate-5020 -
  • fortinet fortigate-5060 -
  • fortinet fortigate-50b -
  • fortinet fortigate-5101c -
  • fortinet fortigate-5140b -
  • fortinet fortigate-600c -
  • fortinet fortigate-60c -
  • fortinet fortigate-620b -
  • fortinet fortigate-800c -
  • fortinet fortigate-80c -
  • fortinet fortigaterugged-100c -
  • fortinet fortigate-voice-80c -
  • fortinet fortios 4.3.10
  • fortinet fortios 5.0
  • fortinet fortios 5.0.1
  • fortinet fortios up to 4.3.12

References

  • CVE: CVE-2013-1414
  • URL: http://www.fortiguard.com/advisory/FGA-2013-22/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out