QID 43948
Date Published: 2023-02-08
QID 43948: FortiOS - Improper Access Control Vulnerability (FG-IR-22-174)
An improper access control [CWE-284] vulnerability in FortiOS may allow a remote authenticated read-only user to modify the interface settings via the API.
Affected Versions:
FortiOS version 7.2.0
FortiOS version 7.0.0 through 7.0.7
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow Improper Access Control vulnerability.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-174
Vendor References
- FG-IR-22-174 -
www.fortiguard.com/psirt/FG-IR-22-174
CVEs related to QID 43948
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-174 |
|