QID 44104
Date Published: 2023-11-08
QID 44104: FortiOS REST API Trusted Host Bypass Vulnerability (FG-IR-23-139)
An improper access control vulnerability [CWE-284] in the FortiOS REST API component may allow an authenticated attacker to access a restricted resource from a non trusted host..
Affected Versions:
FortiOS version 7.4.0
FortiOS version 7.2.0 through 7.2.4
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allow an authenticated attacker to access a restricted resource from a non trusted host.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-139
Vendor References
- FG-IR-23-139 -
www.fortiguard.com/psirt/FG-IR-23-139
CVEs related to QID 44104
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-139 |
|