Improper Access Control in FortiManager Management Interface
CVE-2023-41679
7.7HIGH
Summary
An improper access control vulnerability exists in the FortiManager management interface that may allow a remote and authenticated attacker, possessing at least 'device management' permissions and belonging to a specific Administrative Domain (ADOM), to modify and delete Command Line Interface (CLI) scripts across different ADOMs. This vulnerability could compromise the system's integrity and security, posing a significant risk to users and organizations utilizing the affected FortiManager versions.
Affected Version(s)
FortiManager 7.2.0 <= 7.2.2
FortiManager 7.0.0 <= 7.0.7
FortiManager 6.4.0 <= 6.4.11
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved