Vulnerabilità ed exploit

RUGGEDCOM APE1808 Espongono Richieste HTTP Non Loggate

Siemens ha pubblicato un aggiornamento per RUGGEDCOM APE1808 che corregge vulnerabilità legate a Fortinet FortiOS. Quattro CVE di HTTP request smuggling possono permettere a un attaccante non autenticato di far transitare richieste HTTP non registrate.

1 fonte · 12 mar

CVE-2026-24858

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100º percentile).

Data di correzione federale CISA 30 gen · data superata

CVE-2025-64157

NVD KEV

CVSS 6.7 MEDIUM: a use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0… EPSS 1% (71º percentile).

CVE-2025-55018

NVD KEV

CVSS 5.8 MEDIUM: an inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0… EPSS 0.4% (30º percentile).

CVE-2025-62439

NVD KEV

CVSS 4.2 MEDIUM: an Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet… EPSS 0.1% (4º percentile).

Cronologia

Fonti

Riepilogo fornitore: Fortinet

Part of the PlainSec briefing for 2026-03-13

Every edition of this story: RUGGEDCOM APE1808 Espongono Richieste HTTP Non Loggate

Altro da oggi