A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortianalyzer | Fortinet | 5.6.0 (including) | 5.6.11 (including) |
Fortianalyzer | Fortinet | 6.0.0 (including) | 6.0.11 (including) |
Fortianalyzer | Fortinet | 6.2.0 (including) | 6.2.9 (including) |
Fortianalyzer | Fortinet | 6.4.0 (including) | 6.4.7 (including) |
Fortianalyzer | Fortinet | 7.0.0 (including) | 7.0.3 (excluding) |
Fortimanager | Fortinet | 5.6.0 (including) | 5.6.11 (including) |
Fortimanager | Fortinet | 6.0.0 (including) | 6.0.11 (including) |
Fortimanager | Fortinet | 6.2.0 (including) | 6.2.9 (including) |
Fortimanager | Fortinet | 6.4.0 (including) | 6.4.7 (including) |
Fortimanager | Fortinet | 7.0.0 (including) | 7.0.3 (excluding) |