CVE-2022-42471

MEDIUM

Fortinet Fortiweb < 6.3.21 - Injection

Title source: rule
STIX 2.1

Description

An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attacker to inject arbitrary headers.

Scores

CVSS v3 5.4
EPSS 0.0027
EPSS Percentile 50.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-113 CWE-74
Status published
Products (7)
fortinet/fortiweb 6.4.0
fortinet/fortiweb 6.4.1
fortinet/fortiweb 6.4.2
fortinet/fortiweb 7.0.0
fortinet/fortiweb 7.0.1
fortinet/fortiweb 7.0.2
fortinet/fortiweb 6.3.6 - 6.3.21
Published Jan 03, 2023
Tracked Since Feb 18, 2026