A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortideceptor | Fortinet | 1.0 (including) | 3.3.3 (excluding) |
Fortideceptor | Fortinet | 4.0.0 (including) | 4.0.2 (including) |
Fortideceptor | Fortinet | 4.1.0 (including) | 4.1.0 (including) |
Fortisandbox | Fortinet | 2.5.0 (including) | 3.2.4 (excluding) |
Fortisandbox | Fortinet | 4.0.0 (including) | 4.0.3 (excluding) |
Fortisandbox | Fortinet | 4.2.0 (including) | 4.2.3 (excluding) |