CVE Vulnerabilities

CVE-2022-23443

Published: May 04, 2022 | Modified: Aug 08, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.

Affected Software

Name Vendor Start Version End Version
Fortisoar Fortinet 6.4.0 (including) 6.4.4 (including)
Fortisoar Fortinet 7.0.0 (including) 7.0.2 (including)
Fortisoar Fortinet 6.0.0 (including) 6.0.0 (including)

References