Access Control Flaw in FortiOS by Fortinet
CVE-2022-23442
4.3MEDIUM
What is CVE-2022-23442?
An improper access control vulnerability exists in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.5. This vulnerability could allow an authenticated attacker with limited privileges to execute specific command line interface (CLI) commands, potentially exposing checksum information of other Virtual Domains (VDOMs). This poses a significant risk as it may lead to unauthorized information disclosure, impacting the confidentiality and integrity of the system.
Affected Version(s)
Fortinet FortiOS FortiOS 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.11, 6.2.10, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0