CVE-2005-3058 is an interpretation conflict vulnerability in Fortinet FortiGate 2.8, including FortiOS 2.8MR10 and v3beta, that allows remote attackers to bypass the URL blocker. This bypass can be achieved by sending an HTTP request terminated with a line feed (LF) instead of a carriage return line feed (CRLF), or by omitting the Host field in the HTTP request. With a CVSS score of 7.5, this vulnerability is considered high severity, indicating a network-based attack with low complexity that could lead to partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8_mr10CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
<= 3_betaCPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
2.8CPE matchmatch criteria | cpe:2.3:h:fortinet:fortigate:2.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.