PT-2023-5204 · Fortinet · Fortianalyzer+1

Published

2023-06-25

·

Updated

2023-09-15

·

CVE-2023-36638

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FortiManager versions 6.0 through 7.2.2 FortiAnalyzer versions 6.0 through 7.2.2
Description The issue is related to improper privilege management, which may allow a remote and authenticated API admin user to access certain system settings, such as mail server settings, through the API via a stolen GUI session ID. This could potentially lead to unauthorized access to protected information and elevated privileges.
Recommendations For FortiManager versions 6.0 through 7.2.2, consider restricting access to the API and system settings to minimize the risk of exploitation. For FortiAnalyzer versions 6.0 through 7.2.2, consider restricting access to the API and system settings to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2023-05810
CVE-2023-36638

Affected Products

Fortianalyzer
Fortimanager