PT-2023-5204 · Fortinet · Fortianalyzer+1
Published
2023-06-25
·
Updated
2023-09-15
·
CVE-2023-36638
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FortiManager versions 6.0 through 7.2.2
FortiAnalyzer versions 6.0 through 7.2.2
Description
The issue is related to improper privilege management, which may allow a remote and authenticated API admin user to access certain system settings, such as mail server settings, through the API via a stolen GUI session ID. This could potentially lead to unauthorized access to protected information and elevated privileges.
Recommendations
For FortiManager versions 6.0 through 7.2.2, consider restricting access to the API and system settings to minimize the risk of exploitation.
For FortiAnalyzer versions 6.0 through 7.2.2, consider restricting access to the API and system settings to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortianalyzer
Fortimanager