CVE Vulnerabilities

CVE-2023-44252

Improper Authentication

Published: Dec 13, 2023 | Modified: Dec 18, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token values.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Fortiwan Fortinet 5.1.1 (including) 5.1.1 (including)
Fortiwan Fortinet 5.1.2 (including) 5.1.2 (including)
Fortiwan Fortinet 5.2.0 (including) 5.2.0 (including)
Fortiwan Fortinet 5.2.1 (including) 5.2.1 (including)

Potential Mitigations

References