CVE Vulnerabilities

CVE-2022-38380

Published: Nov 02, 2022 | Modified: Nov 04, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 7.0.0 (including) 7.0.7 (including)
Fortios Fortinet 7.2.0 (including) 7.2.0 (including)

References