CVE-2013-1414

UnknownEPSS 2.29%

Last modified

CVE-2013-1414 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.

Metrics

EPSS Probability
2.29%

80.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FortinetFortios<= 4.3.12
FortinetFortios4.3.10
FortinetFortios5.0
FortinetFortios5.0.1
FortinetFortigate-1000cAll versions
FortinetFortigate-100dAll versions
FortinetFortigate-110cAll versions
FortinetFortigate-1240bAll versions
FortinetFortigate-200bAll versions
FortinetFortigate-20cAll versions
FortinetFortigate-300cAll versions
FortinetFortigate-3040bAll versions
FortinetFortigate-310bAll versions
FortinetFortigate-311bAll versions
FortinetFortigate-3140bAll versions
FortinetFortigate-3240cAll versions
FortinetFortigate-3810aAll versions
FortinetFortigate-3950bAll versions
FortinetFortigate-40cAll versions
FortinetFortigate-5001a-SwAll versions
FortinetFortigate-5001bAll versions
FortinetFortigate-5020All versions
FortinetFortigate-5060All versions
FortinetFortigate-50bAll versions
FortinetFortigate-5101cAll versions
FortinetFortigate-5140bAll versions
FortinetFortigate-600cAll versions
FortinetFortigate-60cAll versions
FortinetFortigate-620bAll versions
FortinetFortigate-800cAll versions
FortinetFortigate-80cAll versions
FortinetFortigate-Voice-80cAll versions
FortinetFortigaterugged-100cAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-1414?
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
How severe is CVE-2013-1414?
Severity scoring for CVE-2013-1414 is pending analysis. The EPSS model estimates a 2.29% probability of exploitation in the next 30 days.
How do I fix CVE-2013-1414?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-1414?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST