Access Control Flaw in FortiOS by Fortinet
CVE-2022-23442
Summary
An improper access control vulnerability exists in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.5. This vulnerability could allow an authenticated attacker with limited privileges to execute specific command line interface (CLI) commands, potentially exposing checksum information of other Virtual Domains (VDOMs). This poses a significant risk as it may lead to unauthorized information disclosure, impacting the confidentiality and integrity of the system.
Affected Version(s)
Fortinet FortiOS FortiOS 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.11, 6.2.10, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved