Improper Access Control in Fortinet FortiIsolator Logging Component
CVE-2024-32124
4MEDIUM
What is CVE-2024-32124?
An improper access control vulnerability exists in the logging component of Fortinet's FortiIsolator versions 2.4.4, 2.4.3, and all versions of 2.3. This issue may allow a remote authenticated attacker to manipulate log entries through specially crafted HTTP requests, potentially compromising the integrity of log data and facilitating further exploitation.
Affected Version(s)
FortiIsolator 2.4.3 <= 2.4.4
FortiIsolator 2.3.0 <= 2.3.4