Improper Privilege Management in Fortinet's FortiManager and FortiAnalyzer API
CVE-2023-36638

4.2MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
13 September 2023

Summary

An improper privilege management vulnerability has been identified in Fortinet's FortiManager and FortiAnalyzer APIs. This issue allows a remote and authenticated API admin user to access sensitive system settings, including mail server configurations, by exploiting a stolen GUI session ID. Such unauthorized access could lead to significant security risks, potentially compromising the integrity and confidentiality of critical system data.

Affected Version(s)

FortiAnalyzer 7.2.0 <= 7.2.2

FortiAnalyzer 7.0.0 <= 7.0.7

FortiAnalyzer 6.4.0 <= 6.4.11

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.