Improper Privilege Management in Fortinet's FortiManager and FortiAnalyzer API
CVE-2023-36638
4.2MEDIUM
Summary
An improper privilege management vulnerability has been identified in Fortinet's FortiManager and FortiAnalyzer APIs. This issue allows a remote and authenticated API admin user to access sensitive system settings, including mail server configurations, by exploiting a stolen GUI session ID. Such unauthorized access could lead to significant security risks, potentially compromising the integrity and confidentiality of critical system data.
Affected Version(s)
FortiAnalyzer 7.2.0 <= 7.2.2
FortiAnalyzer 7.0.0 <= 7.0.7
FortiAnalyzer 6.4.0 <= 6.4.11
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved