QID 377722

Date Published: 2022-11-01

QID 377722: FortiManager - Unauthorized Control Sphere Vulnerability (FG-IR-21-165)

An exposure of sensitive information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.

QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager.

Affected Products:
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.4.0 through 6.4.7
FortiManager version 7.0.0 through 7.0.2

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-165

    Vendor References

    CVEs related to QID 377722

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-165 URL Logo www.fortiguard.com/psirt/FG-IR-21-165