CVE Vulnerabilities

CVE-2023-36638

Published: Sep 13, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 6.0.0 (including) 6.4.12 (excluding)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.8 (excluding)
Fortianalyzer Fortinet 7.2.0 (including) 7.2.3 (excluding)
Fortimanager Fortinet 6.4.0 (including) 6.4.12 (excluding)
Fortimanager Fortinet 7.0.0 (including) 7.0.8 (excluding)
Fortimanager Fortinet 7.2.0 (including) 7.2.3 (excluding)

References