Improper Access Control in FortiMail by Fortinet
CVE-2022-39945

5.4MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
2 November 2022

Summary

An improper access control vulnerability has been identified in FortiMail, which allows authenticated admin users assigned to a specific domain to gain unauthorized access to the information of other domains. This vulnerability may be exploited through insecure direct object references (IDOR), provided that the attacker has valid admin credentials, giving them the ability to modify sensitive domain information unlawfully. It's crucial for organizations utilizing affected FortiMail versions to apply necessary patches and limit the administrative privileges appropriately to safeguard against potential exploitation.

Affected Version(s)

Fortinet FortiMail FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.