QID 44177
Date Published: 2024-03-14
QID 44177: Fortinet FortiOS Authorization bypass in SSLVPN bookmarks Improper access control (FG-IR-24-013)
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS and FortiProxy SSLVPN may allow an authenticated attacker to gain access to another users bookmark via URL manipulation.
Affected Versions:
FortiOS-7.4
FortiOS-7.2
FortiOS-7.0
FortiOS-6.4
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may lead to Improper access control
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-24-013
Vendor References
- FG-IR-24-013 -
www.fortiguard.com/psirt/FG-IR-24-013
CVEs related to QID 44177
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-24-013 |
|