← Back to CVE List
Vulnerability Intelligence Report

CVE-2005-3058

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:3.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
fortinet fortios all
fortinet fortigate 2.8

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.101%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2005-09-26T00:00:00
Published2006-02-14T19:00:00
Patch Date2006-02-13
Last Updated2024-08-07T22:53:30

LINK COPIED TO CLIPBOARD