Fortinet FortiProxy
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*
- >= 7.6.0, <= 7.6.3
- ~7.4
- ~7.2
- ~7.0.1, <= 7.0.21
A vulnerability allowing authenticated proxy users to bypass domain fronting protection has been identified in Fortinet FortiProxy versions 7.6.0 through 7.6.3, as well as in Fortinet FortiOS versions 7.6.0 through 7.6.3. The vulnerability arises from an improperly implemented security check, which may allow users to manipulate HTTP requests and bypass protections intended to prevent domain fronting.
Exploitation of this vulnerability allows for improper access control, enabling authenticated users to bypass security features designed to protect against domain fronting.
Users are advised to upgrade Fortinet FortiProxy to version 7.6.4 or above. For Fortinet FortiOS, the same version upgrade is recommended. After upgrading, Fortinet FortiProxy users should modify the domain-fronting setting to 'strict' to block Host header and SNI mismatches when using domain or IP.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.