QID 379504
Date Published: 2024-03-18
QID 379504: Fortinet FortiManager - Improper Access Control Vulnerability (FG-IR-23-103)
FortiManager provides automation-driven centralized management of your Fortinet devices from a single console.
CVE-2023-36554: An improper access control vulnerability in FortiWLM MEA for FortiManager may allow an unauthenticated remote attacker to execute arbitrary code or commands via specifically crafted requests.
Affected Products:
FortiManager version 7.4.0.
FortiManager version 7.2.0 to 7.2.3.
FortiManager version 7.0.0 to 7.0.10.
FortiManager version 6.4.0 to 6.4.13.
FortiManager 6.2 all versions.
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Note: The QID is marked as Potential as the workaround has been provided by the vendor.
Successful exploitation of this vulnerability may allow attacker to execute unauthorized code or commands via specially crafted HTTP requests.
For more details refer advisory FG-IR-23-103.
Workaround:
The FortiWLM MEA is not installed by default on FortiManager and can be disabled as a workaround.
- FG-IR-23-103 -
www.fortiguard.com/psirt/FG-IR-23-103
CVEs related to QID 379504
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-103 |
|