Improper Access Control in FortiManager Management Interface
CVE-2023-41679

7.7HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
10 October 2023

Summary

An improper access control vulnerability exists in the FortiManager management interface that may allow a remote and authenticated attacker, possessing at least 'device management' permissions and belonging to a specific Administrative Domain (ADOM), to modify and delete Command Line Interface (CLI) scripts across different ADOMs. This vulnerability could compromise the system's integrity and security, posing a significant risk to users and organizations utilizing the affected FortiManager versions.

Affected Version(s)

FortiManager 7.2.0 <= 7.2.2

FortiManager 7.0.0 <= 7.0.7

FortiManager 6.4.0 <= 6.4.11

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.