An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortisoar | Fortinet | 6.4.0 (including) | 6.4.4 (including) |
Fortisoar | Fortinet | 7.0.0 (including) | 7.0.3 (excluding) |
Fortisoar | Fortinet | 7.2.0 (including) | 7.2.0 (including) |