SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Fortinet FortiWeb ApacheCookie_parse authentication bypass attempt
This rule looks for HTTP requests targeting the FortiWeb system API endpoint that contain a forged admin authentication cookie. Successful exploitation grants unauthorized administrative access to the device.
This rule fires on attempts to bypass authentication on Fortinet FortiWeb web application servers.
No public information
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2025-64447 |
Loading description
|