QID 44010
Date Published: 2023-04-17
QID 44010: Fortinet FortiOS Improper Access Control Vulnerability (FG-IR-22-381)
A permissive list of allowed inputs vulnerability in FortiGate Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an authenticated SSL-VPN user to bypass the policy
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-381
Vendor References
- FG-IR-22-381 -
www.fortiguard.com/psirt/FG-IR-22-381
CVEs related to QID 44010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-381 |
|