PT-2023-6007 · Fortinet · Fortimanager
Published
2023-10-10
·
Updated
2023-10-13
·
CVE-2023-41679
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiManager versions 6.0 through 7.2.2
Description
The issue is related to improper access control in the FortiManager management interface. This can allow a remote and authenticated attacker with at least "device management" permission on their profile and belonging to a specific ADOM to add and delete CLI scripts on other ADOMs.
Recommendations
For FortiManager versions 6.0 through 7.2.2, consider restricting access to the management interface to minimize the risk of exploitation. As a temporary workaround, limit the "device management" permission to only necessary profiles and ADOMs until a patch is available. Restrict the ability to add and delete CLI scripts on other ADOMs to prevent unauthorized changes.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortimanager