QID 43911
Date Published: 2022-10-17
QID 43911: FortiOS Improper Inter-Virtual domains (VDOM) Access Control Vulnerability (FG-IR-21-147)
An improper access control vulnerability [CWE-284] in FortiOS may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.
Affected Products:
FortiOS version 6.2.0 through 6.2.10
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable version of FortiOS may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-147
Vendor References
- FG-IR-21-147 -
www.fortiguard.com/psirt/FG-IR-21-147
CVEs related to QID 43911
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-147 |
|