FortiOS

CVE-2022-23439: Externally controlled reference to a resource in another sphere in FortiTester, FortiOS and others

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 3.1 4.1
EPSS0.45%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
FortiTester 7.2.0 to 7.2.17.2.2 or later
FortiTester 7.1.0 to 7.1.1Upgrade past 7.1.1; see the advisory
FortiTester 7.0See the advisory
FortiTester 4.2.0 to 4.2.1Upgrade past 4.2.1; see the advisory
FortiTester 4.1.0 to 4.1.1Upgrade past 4.1.1; see the advisory
FortiTester 4.0See the advisory
FortiTester 3.9.0 to 3.9.2Upgrade past 3.9.2; see the advisory
FortiTester 3.8See the advisory
FortiTester 3.7.0 to 3.7.1Upgrade past 3.7.1; see the advisory
FortiTester 3.6See the advisory
FortiTester 3.5.0 to 3.5.1Upgrade past 3.5.1; see the advisory
FortiTester 3.4See the advisory
FortiTester 3.3.0 to 3.3.1Upgrade past 3.3.1; see the advisory
FortiOS 7.27.2.5 or later
FortiOS 7.0.0 to 7.0.57.0.12 or later
FortiOS 6.4.0 to 6.4.166.4.13 or later
FortiOS 6.2.0 to 6.2.17Upgrade past 6.2.17; see the advisory
FortiOS 6.0.0 to 6.0.18Upgrade past 6.0.18; see the advisory
FortiOS 6.46.4.* or later
FortiRecorder 6.4.0 to 6.4.26.4.3 or later
FortiRecorder 6.0.0 to 6.0.106.0.11 or later
FortiRecorder 2.7.0 to 2.7.7Upgrade past 2.7.7; see the advisory
FortiRecorder 2.6.0 to 2.6.3Upgrade past 2.6.3; see the advisory
FortiNDR 7.27.2.1 or later
FortiNDR 7.17.1.1 or later
FortiNDR 7.0.0 to 7.0.7Upgrade past 7.0.7; see the advisory
FortiNDR 1.5.0 to 1.5.3Upgrade past 1.5.3; see the advisory
FortiNDR 1.4See the advisory
FortiNDR 1.3.0 to 1.3.1Upgrade past 1.3.1; see the advisory
FortiNDR 1.2See the advisory
FortiNDR 1.1See the advisory
FortiADC 7.0.0 to 7.0.17.0.2 or later
FortiADC 6.2.0 to 6.2.36.2.4 or later
FortiADC 6.1.0 to 6.1.6Upgrade past 6.1.6; see the advisory
FortiADC 6.0.0 to 6.0.4Upgrade past 6.0.4; see the advisory
FortiADC 5.4.0 to 5.4.5Upgrade past 5.4.5; see the advisory
FortiADC 5.3.0 to 5.3.7Upgrade past 5.3.7; see the advisory
FortiADC 5.2.0 to 5.2.8Upgrade past 5.2.8; see the advisory
FortiADC 5.1.0 to 5.1.7Upgrade past 5.1.7; see the advisory
FortiADC 5.0.0 to 5.0.4Upgrade past 5.0.4; see the advisory
FortiManager 7.4.0 to 7.4.3Upgrade past 7.4.3; see the advisory
FortiManager 7.2.0 to 7.2.11Upgrade past 7.2.11; see the advisory
FortiManager 7.0.0 to 7.0.15Upgrade past 7.0.15; see the advisory
FortiManager 6.4.0 to 6.4.15Upgrade past 6.4.15; see the advisory
FortiManager 6.2.0 to 6.2.13Upgrade past 6.2.13; see the advisory
FortiVoice 7.0.0 to 7.0.17.0.2 or later
FortiVoice 6.4.0 to 6.4.86.4.9 or later
FortiVoice 6.0.0 to 6.0.11Upgrade past 6.0.11; see the advisory
FortiSOAR on-premise 7.2.0 to 7.2.2Upgrade past 7.2.2; see the advisory
FortiSOAR on-premise 7.0.0 to 7.0.3Upgrade past 7.0.3; see the advisory
FortiSOAR on-premise 6.4.3 to 6.4.4Upgrade past 6.4.4; see the advisory
FortiSOAR on-premise 6.4.0 to 6.4.1Upgrade past 6.4.1; see the advisory
FortiDDoS 5.5.0 to 5.5.15.5.2 or later
FortiDDoS 5.4.0 to 5.4.3Upgrade past 5.4.3; see the advisory
FortiDDoS 5.3.0 to 5.3.2Upgrade past 5.3.2; see the advisory
FortiDDoS 5.2See the advisory
FortiDDoS 5.1See the advisory
FortiDDoS 5.0See the advisory
FortiDDoS 4.7See the advisory
FortiDDoS 4.6See the advisory
FortiDDoS 4.5See the advisory
FortiWLC 8.6.0 to 8.6.78.6.7 or later
FortiWLC 8.5.0 to 8.5.5Upgrade past 8.5.5; see the advisory
FortiWLC 8.4.4 to 8.4.8Upgrade past 8.4.8; see the advisory
FortiWLC 8.4.0 to 8.4.2Upgrade past 8.4.2; see the advisory
FortiAnalyzer 7.4.0 to 7.4.2Upgrade past 7.4.2; see the advisory
FortiAnalyzer 7.2.0 to 7.2.11Upgrade past 7.2.11; see the advisory
FortiAnalyzer 7.0.0 to 7.0.15Upgrade past 7.0.15; see the advisory
FortiAnalyzer 6.4.0 to 6.4.15Upgrade past 6.4.15; see the advisory
FortiAnalyzer 6.2.0 to 6.2.13Upgrade past 6.2.13; see the advisory
FortiPortal 6.0.0 to 6.0.9Upgrade past 6.0.9; see the advisory
FortiAuthenticator 6.4.0 to 6.4.16.4.2 or later
FortiAuthenticator 6.3.0 to 6.3.36.3.4 or later
FortiAuthenticator 6.2.0 to 6.2.2Upgrade past 6.2.2; see the advisory
FortiAuthenticator 6.1.0 to 6.1.3Upgrade past 6.1.3; see the advisory
FortiAuthenticator 6.0.0 to 6.0.8Upgrade past 6.0.8; see the advisory
FortiAuthenticator 5.5See the advisory
FortiAuthenticator 5.4.0 to 5.4.1Upgrade past 5.4.1; see the advisory
FortiAuthenticator 5.3.0 to 5.3.1Upgrade past 5.3.1; see the advisory
FortiAuthenticator 5.2.0 to 5.2.2Upgrade past 5.2.2; see the advisory
FortiAuthenticator 5.1.0 to 5.1.2Upgrade past 5.1.2; see the advisory
FortiMail 7.0.0 to 7.0.37.0.4 or later
FortiMail 6.4.0 to 6.4.8Upgrade past 6.4.8; see the advisory
FortiMail 6.2.0 to 6.2.9Upgrade past 6.2.9; see the advisory
FortiMail 6.0.0 to 6.0.12Upgrade past 6.0.12; see the advisory
FortiMail 5.4.0 to 5.4.12Upgrade past 5.4.12; see the advisory
FortiDDoS-F 6.3.0 to 6.3.36.3.4 or later
FortiDDoS-F 6.2.0 to 6.2.3Upgrade past 6.2.3; see the advisory
FortiDDoS-F 6.1.0 to 6.1.5Upgrade past 6.1.5; see the advisory
FortiSwitch 7.0.0 to 7.0.47.0.5 or later
FortiSwitch 6.4.0 to 6.4.106.4.11 or later
FortiSwitch 6.2.0 to 6.2.8Upgrade past 6.2.8; see the advisory
FortiSwitch 6.0.0 to 6.0.7Upgrade past 6.0.7; see the advisory
FortiProxy 7.0.0 to 7.0.4Upgrade past 7.0.4; see the advisory
FortiProxy 2.0.0 to 2.0.14Upgrade past 2.0.14; see the advisory
FortiProxy 1.2.0 to 1.2.13Upgrade past 1.2.13; see the advisory
FortiProxy 1.1.0 to 1.1.6Upgrade past 1.1.6; see the advisory
FortiProxy 1.0.0 to 1.0.7Upgrade past 1.0.7; see the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.