Improper Access Control in Fortinet FortiSOAR Affects Gateway API Data
CVE-2022-23443
7.5HIGH
What is CVE-2022-23443?
Fortinet FortiSOAR prior to version 7.2.0 suffers from an improper access control vulnerability that allows unauthenticated attackers to gain access to sensitive gateway API data through specially crafted HTTP GET requests. This flaw can potentially expose critical information and lead to further exploitation if not addressed promptly.
Affected Version(s)
Fortinet FortiSOAR FortiSOAR 7.0.2, 7.0.1, 7.0.0, 6.4.4, 6.4.3, 6.4.1, 6.4.0, 6.0.0, 5.x.x