CVE Vulnerabilities

CVE-2022-38377

Published: Nov 25, 2022 | Modified: Nov 07, 2023
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 6.0.0 (including) 6.0.12 (including)
Fortianalyzer Fortinet 6.2.0 (including) 6.2.10 (including)
Fortianalyzer Fortinet 6.4.0 (including) 6.4.8 (including)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.3 (including)
Fortianalyzer Fortinet 7.2.0 (including) 7.2.0 (including)
Fortimanager Fortinet 6.0.0 (including) 6.0.11 (including)
Fortimanager Fortinet 6.2.0 (including) 6.2.9 (including)
Fortimanager Fortinet 6.4.0 (including) 6.4.7 (including)
Fortimanager Fortinet 7.0.0 (including) 7.0.3 (including)
Fortimanager Fortinet 7.2.0 (including) 7.2.0 (including)

References