PT-2024-1070 · Fortinet · Fortiportal

Published

2024-01-09

·

Updated

2024-01-17

·

CVE-2023-46712

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiPortal versions 7.0.0 through 7.0.6 Fortinet FortiPortal versions 7.2.0 through 7.2.1
Description The issue is related to improper access control in Fortinet FortiPortal, which can be exploited by an attacker to escalate privileges via specifically crafted HTTP requests. This can allow a remote attacker to increase their privileges by sending specially formed HTTP requests.
Recommendations For Fortinet FortiPortal versions 7.0.0 through 7.0.6, consider restricting access to the affected HTTP endpoints until a patch is available. For Fortinet FortiPortal versions 7.2.0 through 7.2.1, consider disabling the functionality that allows privilege escalation via crafted HTTP requests until a fix is provided. As a temporary workaround, avoid using the affected versions of Fortinet FortiPortal for critical operations that require high privilege levels.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-00307
CVE-2023-46712

Affected Products

Fortiportal