CVE Vulnerabilities

CVE-2023-44252

Improper Authentication

Published: Dec 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token values.

Weakness 

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software 

Name Vendor Start Version End Version
Fortiwan Fortinet 5.1.1 (including) 5.1.1 (including)
Fortiwan Fortinet 5.1.2 (including) 5.1.2 (including)
Fortiwan Fortinet 5.2.0 (including) 5.2.0 (including)
Fortiwan Fortinet 5.2.1 (including) 5.2.1 (including)

Potential Mitigations 

References