An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
| Vendor | Product | Versions |
|---|---|---|
| fortinet | fortiproxy | 7.0.0, 7.2.0, 7.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fortinet | fortios | cve_cpe | 95% |
Added new CWE ID related to authentication bypass and included the tag 'FortiBleed'.
Initial creation