Improper Access Control in FortiOS Affects Remote Users
CVE-2022-38380
4.3MEDIUM
Summary
An improper access control vulnerability exists in FortiOS versions 7.2.0 and 7.0.0 through 7.0.7, which could allow a remote authenticated user with read-only privileges to modify interface settings through the API. This flaw poses a security risk by enabling unauthorized alterations, potentially compromising the integrity of device configurations.
Affected Version(s)
Fortinet FortiOS FortiOS 7.2.0, 7.0.7, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved