HTTP response splitting in FortiOS - CVE-2022-42472

 

HTTP response splitting in FortiOS - CVE-2022-42472

Published: February 17, 2023


Vulnerability identifier: #VU72347
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42472
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform HTTP splitting attacks.

The vulnerability exists due to software does not correctly process CRLF character sequences. A remote user can send specially crafted request containing CRLF sequence and inject arbitrary HTTP headers.

Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.


Affected software

FortiOS
FortiProxy

How to mitigate CVE-2022-42472

Install updates from vendor's website.

FortiOS - addressed in versions 7.0.9, 7.2.3
FortiProxy - addressed in versions 2.0.11, 7.0.8, 7.2.2

External References

Related Security Bulletins