QID 377722
Date Published: 2022-11-01
QID 377722: FortiManager - Unauthorized Control Sphere Vulnerability (FG-IR-21-165)
An exposure of sensitive information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager.
Affected Products:
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.4.0 through 6.4.7
FortiManager version 7.0.0 through 7.0.2
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-165
Vendor References
- FG-IR-21-165 -
www.fortiguard.com/psirt/FG-IR-21-165
CVEs related to QID 377722
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-165 |
|