A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
Published Jan 22, 2025
6.1
MEDIUMCVSS 3.1
EPSS 0.45%
Description
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
Affected products
-
- Version 5.0.0StatusaffectedConstraints<=5.0.4
- Version 5.1.0StatusaffectedConstraints<=5.1.7
- Version 5.2.0StatusaffectedConstraints<=5.2.8
- Version 5.3.0StatusaffectedConstraints<=5.3.7
- Version 5.4.0StatusaffectedConstraints<=5.4.5
- Version 6.0.0StatusaffectedConstraints<=6.0.4
- Version 6.1.0StatusaffectedConstraints<=6.1.6
- Version 6.2.0StatusaffectedConstraints<=6.2.3
- Version 7.0.0StatusaffectedConstraints<=7.0.1
- Version
-
- Version 6.2.0StatusaffectedConstraints<=6.2.13
- Version 6.4.0StatusaffectedConstraints<=6.4.15
- Version 7.0.0StatusaffectedConstraints<=7.0.15
- Version 7.2.0StatusaffectedConstraints<=7.2.11
- Version 7.4.0StatusaffectedConstraints<=7.4.2
- Version
-
- Version 5.1.0StatusaffectedConstraints<=5.1.2
- Version 5.2.0StatusaffectedConstraints<=5.2.2
- Version 5.3.0StatusaffectedConstraints<=5.3.1
- Version 5.4.0StatusaffectedConstraints<=5.4.1
- Version 5.5.0StatusaffectedConstraints-
- Version 6.0.0StatusaffectedConstraints<=6.0.8
- Version 6.1.0StatusaffectedConstraints<=6.1.3
- Version 6.2.0StatusaffectedConstraints<=6.2.2
- Version 6.3.0StatusaffectedConstraints<=6.3.3
- Version 6.4.0StatusaffectedConstraints<=6.4.1
- Version
-
- Version 4.5.0StatusaffectedConstraints-
- Version 4.6.0StatusaffectedConstraints-
- Version 4.7.0StatusaffectedConstraints-
- Version 5.0.0StatusaffectedConstraints-
- Version 5.1.0StatusaffectedConstraints-
- Version 5.2.0StatusaffectedConstraints-
- Version 5.3.0StatusaffectedConstraints<=5.3.2
- Version 5.4.0StatusaffectedConstraints<=5.4.3
- Version 5.5.0StatusaffectedConstraints<=5.5.1
- Version
-
- Version 6.1.0StatusaffectedConstraints<=6.1.5
- Version 6.2.0StatusaffectedConstraints<=6.2.3
- Version 6.3.0StatusaffectedConstraints<=6.3.3
- Version
-
- Version 5.4.0StatusaffectedConstraints<=5.4.12
- Version 6.0.0StatusaffectedConstraints<=6.0.12
- Version 6.2.0StatusaffectedConstraints<=6.2.9
- Version 6.4.0StatusaffectedConstraints<=6.4.8
- Version 7.0.0StatusaffectedConstraints<=7.0.3
- Version
-
- Version 6.2.0StatusaffectedConstraints<=6.2.13
- Version 6.4.0StatusaffectedConstraints<=6.4.15
- Version 7.0.0StatusaffectedConstraints<=7.0.15
- Version 7.2.0StatusaffectedConstraints<=7.2.11
- Version 7.4.0StatusaffectedConstraints<=7.4.3
- Version
-
- Version 1.1.0StatusaffectedConstraints-
- Version 1.2.0StatusaffectedConstraints-
- Version 1.3.0StatusaffectedConstraints<=1.3.1
- Version 1.4.0StatusaffectedConstraints-
- Version 1.5.0StatusaffectedConstraints<=1.5.3
- Version 7.0.0StatusaffectedConstraints<=7.0.7
- Version 7.1.0StatusaffectedConstraints-
- Version 7.2.0StatusaffectedConstraints-
- Version
-
- Version 6.0.0StatusaffectedConstraints<=6.0.18
- Version 6.2.0StatusaffectedConstraints<=6.2.17
- Version 6.4.0StatusaffectedConstraints<6.4.*
- Version 6.4.0StatusaffectedConstraints<=6.4.16
- Version 7.0.0StatusaffectedConstraints<=7.0.5
- Version 7.2.0StatusaffectedConstraints-
- Version
-
- Version 6.0.0StatusaffectedConstraints<=6.0.9
- Version
-
- Version 1.0.0StatusaffectedConstraints<=1.0.7
- Version 1.1.0StatusaffectedConstraints<=1.1.6
- Version 1.2.0StatusaffectedConstraints<=1.2.13
- Version 2.0.0StatusaffectedConstraints<=2.0.14
- Version 7.0.0StatusaffectedConstraints<=7.0.4
- Version
-
- Version 2.6.0StatusaffectedConstraints<=2.6.3
- Version 2.7.0StatusaffectedConstraints<=2.7.7
- Version 6.0.0StatusaffectedConstraints<=6.0.10
- Version 6.4.0StatusaffectedConstraints<=6.4.2
- Version
-
- Version 6.4.0StatusaffectedConstraints<=6.4.1
- Version 6.4.3StatusaffectedConstraints<=6.4.4
- Version 7.0.0StatusaffectedConstraints<=7.0.3
- Version 7.2.0StatusaffectedConstraints<=7.2.2
- Version
-
- Version 6.0.0StatusaffectedConstraints<=6.0.7
- Version 6.2.0StatusaffectedConstraints<=6.2.8
- Version 6.4.0StatusaffectedConstraints<=6.4.10
- Version 7.0.0StatusaffectedConstraints<=7.0.4
- Version
-
- Version 3.3.0StatusaffectedConstraints<=3.3.1
- Version 3.4.0StatusaffectedConstraints-
- Version 3.5.0StatusaffectedConstraints<=3.5.1
- Version 3.6.0StatusaffectedConstraints-
- Version 3.7.0StatusaffectedConstraints<=3.7.1
- Version 3.8.0StatusaffectedConstraints-
- Version 3.9.0StatusaffectedConstraints<=3.9.2
- Version 4.0.0StatusaffectedConstraints-
- Version 4.1.0StatusaffectedConstraints<=4.1.1
- Version 4.2.0StatusaffectedConstraints<=4.2.1
- Version 7.0.0StatusaffectedConstraints-
- Version 7.1.0StatusaffectedConstraints<=7.1.1
- Version 7.2.0StatusaffectedConstraints<=7.2.1
- Version
-
- Version 6.0.0StatusaffectedConstraints<=6.0.11
- Version 6.4.0StatusaffectedConstraints<=6.4.8
- Version 7.0.0StatusaffectedConstraints<=7.0.1
- Version
-
- Version 8.4.0StatusaffectedConstraints<=8.4.2
- Version 8.4.4StatusaffectedConstraints<=8.4.8
- Version 8.5.0StatusaffectedConstraints<=8.5.5
- Version 8.6.0StatusaffectedConstraints<=8.6.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Fortinet | FortiADC | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiAnalyzer | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiAuthenticator | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiDDoS | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiDDoS-F | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiMail | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiManager | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiNDR | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiOS | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiPortal | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiProxy | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiRecorder | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiSOAR on-premise | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiSwitch | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiTester | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiVoice | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||
| Fortinet | FortiWLC | unaffected |
|
- ≥ 5.4.0 · < 6.2.4
- ≥ 6.3.0 · < 6.3.4
- ≥ 6.4.0 · < 6.4.2
- ≥ 5.3.0 · < 5.5.2
- ≥ 6.1.0 · < 6.3.4
- ≥ 6.4.0 · < 7.0.4
- ≥ 1.4.0 · < 7.1.1
- 7.2.0
- ≥ 2.0.0 · < 7.0.5
- ≥ 7.2.0 · < 7.4.0
- ≥ 6.0.0 · < 6.0.11
- ≥ 6.4.0 · < 6.4.3
- ≥ 6.4.0 · < 7.3.0
- ≥ 3.7.0 · < 7.2.2
- ≥ 6.0.0 · < 6.4.9
- ≥ 8.6.0 · < 8.6.7
- ≥ 6.0.0 · < 7.0.6
- ≥ 7.2.0 · < 7.2.5
- ≥ 6.4.0 · < 7.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
FortiOS Administrative Interface Upgrade to FortiOS version 7.0.6 and above, Upgrade to FortiOS version 7.2.1 and above. AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`: config system global set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection"
SSLVPN interface Upgrade to FortiOS version 7.4.0 or above Upgrade to FortiOS version 7.2.5 or above AND Set the `server-hostname` property to the device hostname, which will disable `Host redirection` for SSL VPN: config vpn ssl settings set server-hostname Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
Webfilter interface (port 8008) Upgrade to FortiOS version 7.4.0 or above Upgrade to FortiOS version 7.2.5 or above Upgrade to FortiOS version 7.0.12 or above Upgrade to FortiOS version 6.4.13 or above
FortiProxy Administrative Interface Upgrade to FortiProxy version 7.0.5 and above AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`: config system global set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection"
SSLVPN interface Upgrade to FortiProxy version 7.4.0 or above AND Set the `server-hostname` property to the device hostname, which will disable `Host redirection` for SSL VPN: config vpn ssl settings set server-hostname Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
WebFilter interface (port 8008) Upgrade to FortiProxy version 7.4.0 or above
Upgrade to FortiRecorder version 7.0.0 or above Upgrade to FortiRecorder version 6.4.3 or above Upgrade to FortiRecorder version 6.0.11 or above Upgrade to FortiNDR version 7.4.0 or above
FortiAnalyzer & FortiManager
Upgrade to version 7.6.0 or above Upgrade to version 7.4.4 or above
Set the `admin-host` property to the device hostname, which will disable `Host redirection` for administrative interface. config system global set admin-host end
FortiNDR Upgrade to FortiNDR version 7.2.1 or above Upgrade to FortiNDR version 7.1.1 or above AND Set the `https-redirect-host` property to the device hostname, which will disable `Host redirection`: config system global set https-redirect-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection" end
FortiADC Upgrade to FortiADC version 7.1.0 or above Upgrade to FortiADC version 7.0.2 or above Upgrade to FortiADC version 6.2.4 or above AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`: config system global set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection"
FortiDDOS-F Upgrade to FortiDDoS-F version 6.4.0 or above Upgrade to FortiDDoS-F version 6.3.4 or above AND Set the `admin-host` property to the device hostname, which will disable `Host redirection`: config system global set admin-host "Administrative host for HTTP and HTTPs. When set, will be used in lieu of the client's Host header for any redirection"
Upgrade to FortiSwitch version 7.2.0 or above Upgrade to FortiSwitch version 7.0.5 or above Upgrade to FortiSwitch version 6.4.11 or above Upgrade to FortiVoice version 7.0.2 or above Upgrade to FortiVoice version 6.4.9 or above Upgrade to FortiMail version 7.2.0 or above Upgrade to FortiMail version 7.0.4 or above Upgrade to FortiWLC version 8.6.7 or above Upgrade to FortiAuthenticator version 6.4.2 or above Upgrade to FortiAuthenticator version 6.3.4 or above Upgrade to FortiDDoS version 5.6.0 or above Upgrade to FortiDDoS version 5.5.2 or above Upgrade to FortiSOAR version 7.3.0 or above Upgrade to FortiTester version 7.3.0 or above Upgrade to FortiTester version 7.2.2 or above
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jan 22, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.45% (0.00449) | 36.66th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00429) | 34.01th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00056) | 14.65th | v4 (v2025.03.14) |
| Jan 23, 2025 | 0.04% (0.00043) | 11.40th | v3 (v2023.03.01) |
References (1)
| Link | Providers | Tags |
|---|---|---|
| https://fortiguard.com/psirt/FG-IR-23-494 |
Change history (0)
No recorded changes yet.