PT-2024-2111 · Fortinet · Fortiauthenticator+1

Published

2024-03-12

·

Updated

2024-03-21

·

CVE-2023-46717

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.4.1 and below FortiOS versions 7.2.6 and below FortiOS versions 7.0.12 and below
Description An improper authentication issue in FortiOS, when configured with FortiAuthenticator in HA, may allow a readonly user to gain read-write access via successive login attempts. This is related to weaknesses in the authentication procedure. A remote attacker could exploit this to elevate their privileges.
Recommendations For FortiOS versions 7.4.1 and below, update to a version above 7.4.1 to resolve the issue. For FortiOS versions 7.2.6 and below, update to a version above 7.2.6 to resolve the issue. For FortiOS versions 7.0.12 and below, update to a version above 7.0.12 to resolve the issue. As a temporary workaround, consider restricting access to FortiAuthenticator in HA configurations to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02007
CVE-2023-46717

Affected Products

Fortiauthenticator
Fortios