PT-2024-2111 · Fortinet · Fortiauthenticator+1
Published
2024-03-12
·
Updated
2024-03-21
·
CVE-2023-46717
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.4.1 and below
FortiOS versions 7.2.6 and below
FortiOS versions 7.0.12 and below
Description
An improper authentication issue in FortiOS, when configured with FortiAuthenticator in HA, may allow a readonly user to gain read-write access via successive login attempts. This is related to weaknesses in the authentication procedure. A remote attacker could exploit this to elevate their privileges.
Recommendations
For FortiOS versions 7.4.1 and below, update to a version above 7.4.1 to resolve the issue.
For FortiOS versions 7.2.6 and below, update to a version above 7.2.6 to resolve the issue.
For FortiOS versions 7.0.12 and below, update to a version above 7.0.12 to resolve the issue.
As a temporary workaround, consider restricting access to FortiAuthenticator in HA configurations to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiauthenticator
Fortios