QID 379316
QID 379316: Fortinet FortiADC Improper Access Control Vulnerability(FG-IR-22-518)
A permissive cross-domain policy with untrusted domains (CWE-942) vulnerability in the API of FortiADC may allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
Affected Versions
FortiADC 7.1.0 through 7.1.1
QID Detection Logic (Authenticated)
This qid checks version of FortiADC using commandline
On successful exploitation it may allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
Solution
Vendor has released fix to this issue. Refer FG-IR-22-518 for more details.
Vendor References
- FG-IR-22-518 -
www.fortiguard.com/psirt/FG-IR-22-518
CVEs related to QID 379316
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-518 |
|