QID 377725
Date Published: 2022-11-01
QID 377725: FortiManager and FortiAnalyzer - Privilege Escalation Vulnerability (FG-IR-21-056)
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
Affected Products:
FortiManager version 6.0.0 through 6.0.11
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.4.0 through 6.4.7
FortiManager version 7.0.0 through 7.0.3
FortiAnalyzer version 6.0.0 through 6.0.11
FortiAnalyzer version 6.2.0 through 6.2.9
FortiAnalyzer version 6.4.0 through 6.4.7
FortiAnalyzer version 7.0.0 through 7.0.3
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Vulnerable version may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-156
- FG-IR-21-056 -
www.fortiguard.com/psirt/FG-IR-21-056
CVEs related to QID 377725
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-056 |
|