QID 377727

Date Published: 2022-11-03

QID 377727: FortiManager - Inter ADOM Access Control Vulnerability (FG-IR-21-043)

An improper access control vulnerability [CWE-284] in FortiManager may allow an authenticated attacker with a restricted user profile to modify the VPN tunnel status of other VDOMs using VPN Manager.

Affected Products:
FortiManager version 6.4.4 and 6.4.5

QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager.

Vulnerable version may allow an unauthenticated attacker with a restricted user profile to modify the VPN tunnel status of other VDOMs using VPN Manager.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-043

    Vendor References

    CVEs related to QID 377727

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-043 URL Logo www.fortiguard.com/psirt/FG-IR-21-043