QID 378011
Date Published: 2023-04-24
QID 378011: Fortinet FortiManager Improper Access Control Vulnerability (FG-IR-22-371)
An incorrect user management vulnerability in the FortiManager VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin profiled admin account is deleted.
Affected Products:
FortiManager version 7.0.0 through 7.0.1
FortiManager version 6.4.0 through 6.4.7
FortiManager version 6.2.0 through 6.2.8
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager,FortiAnalyzer
Successful exploitation may lead to Improper access control
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-371
Vendor References
- FG-IR-22-371 -
www.fortiguard.com/psirt/FG-IR-22-371
CVEs related to QID 378011
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-371 |
|