HTTP: Fortigate Firewalls Cross-Site Request Forgery

This signature detects attempts to exploit a known vulnerability against Fortigate Firewalls. A successful attack can lead to cross-site request forgery attacks and unauthorized session hijacks.

Extended Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.

Short Name
HTTP:MISC:FORTIGATE-CSRF
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2013-1414 Cross-Site Firewalls Forgery Fortigate Request
Release Date
07/24/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

5.1

Found a potential security threat?