PT-2023-4880 · Fortinet · Fortiswitchmanager

Publicado

2023-09-07

·

Atualizado

2023-09-12

·

CVE-2023-36635

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiSwitchManager versions 7.0.0 through 7.0.1 Fortinet FortiSwitchManager versions 7.2.0 through 7.2.2
Description The issue is related to improper access control in Fortinet FortiSwitchManager, which may allow a remote authenticated read-only user to modify interface settings via the API. This can be achieved by sending commands through the application programming interface.
Recommendations For Fortinet FortiSwitchManager versions 7.0.0 through 7.0.1, consider restricting access to the API to prevent unauthorized modifications to interface settings until a patch is available. For Fortinet FortiSwitchManager versions 7.2.0 through 7.2.2, consider disabling the API functionality temporarily to minimize the risk of exploitation.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05371
CVE-2023-36635

Produtos afetados

Fortiswitchmanager