CVE-2018-1354
6.5MEDIUM
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 27 June 2018
Summary
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
Affected Version(s)
Fortinet FortiManager, FortiAnalyzer FortiManager 6.0.0, 5.6.5 and below versions
Fortinet FortiManager, FortiAnalyzer FortiAnalyzer 6.0.0, 5.6.5 and below versions
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved