QID 376977
QID 376977: Fortinet FortiManager and FortiAnalyzer - Inter ADOM Information Leakage Vulnerability (FG-IR-20-143)
An improper access control vulnerability [CWE-284] in FortiManager and FortiAnalyzer management interface may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.
Supported Affected Products:
FortiManager version 7.2.0
FortiManager version 7.0.0 through 7.0.3
FortiManager version 6.4.0 through 6.4.7
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.0.0 through 6.0.11
FortiAnalyzer version 7.2.0
FortiAnalyzer version 7.0.0 through 7.0.3
FortiAnalyzer version 6.4.0 through 6.4.8
FortiAnalyzer version 6.2.0 through 6.2.10
FortiAnalyzer version 6.0.0 through 6.0.12
QID Detection Logic(Authenticated):
QID will fire the command to get system status and will match the affected versions.
Vulnerable FortiManager and FortiAnalyzer management interface may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.
- FG-IR-20-143 -
www.fortiguard.com/psirt/FG-IR-20-143
CVEs related to QID 376977
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-143 |
|