PT-2022-6023 · Fortinet · Fortios

Published

2022-11-01

·

Updated

2022-11-04

·

CVE-2022-38380

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.0.0 through 7.0.7 FortiOS version 7.2.0
Description The issue is related to improper access control, which may allow a remote authenticated read-only user to modify interface settings via the API. This could potentially be exploited by a remote attacker to alter settings.
Recommendations For FortiOS versions 7.0.0 through 7.0.7, consider restricting access to the API until a patch is available. For FortiOS version 7.2.0, consider disabling the interface settings modification functionality via the API as a temporary workaround. Avoid using the API for interface settings modification until the issue is resolved.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2022-07475
CVE-2022-38380

Affected Products

Fortios