PT-2024-1070 · Fortinet · Fortiportal
Published
2024-01-09
·
Updated
2024-01-17
·
CVE-2023-46712
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiPortal versions 7.0.0 through 7.0.6
Fortinet FortiPortal versions 7.2.0 through 7.2.1
Description
The issue is related to improper access control in Fortinet FortiPortal, which can be exploited by an attacker to escalate privileges via specifically crafted HTTP requests. This can allow a remote attacker to increase their privileges by sending specially formed HTTP requests.
Recommendations
For Fortinet FortiPortal versions 7.0.0 through 7.0.6, consider restricting access to the affected HTTP endpoints until a patch is available.
For Fortinet FortiPortal versions 7.2.0 through 7.2.1, consider disabling the functionality that allows privilege escalation via crafted HTTP requests until a fix is provided.
As a temporary workaround, avoid using the affected versions of Fortinet FortiPortal for critical operations that require high privilege levels.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiportal