A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortianalyzer | Fortinet | 6.2.0 (including) | 6.2.12 (including) |
Fortianalyzer | Fortinet | 6.4.0 (including) | 6.4.13 (including) |
Fortianalyzer | Fortinet | 7.0.0 (including) | 7.0.9 (including) |
Fortianalyzer | Fortinet | 7.2.0 (including) | 7.2.3 (including) |
Fortianalyzer | Fortinet | 7.4.0 (including) | 7.4.0 (including) |
Fortimanager | Fortinet | 6.2.0 (including) | 6.2.12 (including) |
Fortimanager | Fortinet | 6.4.0 (including) | 6.4.13 (including) |
Fortimanager | Fortinet | 7.0.0 (including) | 7.0.9 (including) |
Fortimanager | Fortinet | 7.2.0 (including) | 7.2.3 (including) |
Fortimanager | Fortinet | 7.4.0 (including) | 7.4.0 (including) |