QID 378862
Date Published: 2023-10-03
QID 378862: Fortinet FortiAnalyzer and FortiManager - Improper Privilege Management Vulnerability (FG-IR-22-522)
An improper privilege management vulnerability [CWE-269] in FortiManager and FortiAnalyzer API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
Affected Products:
FortiManager version 7.2.0 through 7.2.2
FortiManager version 7.0.0 through 7.0.7
FortiManager version 6.4.0 through 6.4.11
FortiManager 6.2 all versions
FortiManager 6.0 all versions
FortiAnalyzer version 7.2.0 through 7.2.2
FortiAnalyzer version 7.0.0 through 7.0.7
FortiAnalyzer version 6.4.0 through 6.4.11
FortiAnalyzer 6.2 all versions
FortiAnalyzer 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Successful exploitation of this vulnerability may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-522
- FG-IR-22-522 -
www.fortiguard.com/psirt/FG-IR-22-522
CVEs related to QID 378862
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-522 |
|