PT-2023-4880 · Fortinet · Fortiswitchmanager
Publicado
2023-09-07
·
Atualizado
2023-09-12
·
CVE-2023-36635
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiSwitchManager versions 7.0.0 through 7.0.1
Fortinet FortiSwitchManager versions 7.2.0 through 7.2.2
Description
The issue is related to improper access control in Fortinet FortiSwitchManager, which may allow a remote authenticated read-only user to modify interface settings via the API. This can be achieved by sending commands through the application programming interface.
Recommendations
For Fortinet FortiSwitchManager versions 7.0.0 through 7.0.1, consider restricting access to the API to prevent unauthorized modifications to interface settings until a patch is available.
For Fortinet FortiSwitchManager versions 7.2.0 through 7.2.2, consider disabling the API functionality temporarily to minimize the risk of exploitation.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fortiswitchmanager