PT-2023-13601 · Fortinet · Fortiproxy+1
CVE-2022-38378
·
Publicado
2023-02-16
·
Atualizado
2023-02-24
CVSS v3.1
6.0
Média
| Vetor | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions prior to 7.0.7
FortiProxy versions 7.2.0 through 7.2.1 and prior to 7.0.7
Description
An improper privilege management issue allows an attacker with access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.
Recommendations
For Fortinet FortiOS versions prior to 7.0.7, update to a version that includes the fix for this issue.
For FortiProxy versions 7.2.0 through 7.2.1 and prior to 7.0.7, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the admin profile section (System subsection Administrator Users) to minimize the risk of exploitation.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fortios
Fortiproxy