QID 377728
Date Published: 2022-11-03
QID 377728: FortiManager and FortiAnalyzer - Inter ADOM Information Leakage Vulnerability (FG-IR-20-143)
An improper access control vulnerability [CWE-284] in FortiManager and FortiAnalyzer management interface may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.
affected Products:
FortiManager version 7.2.0
FortiManager version 7.0.0 through 7.0.3
FortiManager version 6.4.0 through 6.4.7
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.0.0 through 6.0.11
FortiAnalyzer version 7.2.0
FortiAnalyzer version 7.0.0 through 7.0.3
FortiAnalyzer version 6.4.0 through 6.4.8
FortiAnalyzer version 6.2.0 through 6.2.10
FortiAnalyzer version 6.0.0 through 6.0.12
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Vulnerable version may allow a remote and authenticated admin user assigned to specific ADOM to access other ADOMs information such as device information and dashboard information.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-20-143
- FG-IR-20-143 -
www.fortiguard.com/psirt/FG-IR-20-143
CVEs related to QID 377728
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-143 |
|