CVE Vulnerabilities

CVE-2024-36505

Published: Aug 13, 2024 | Modified: Aug 22, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.4.13 (including) 6.4.15 (including)
Fortios Fortinet 7.0.12 (including) 7.0.15 (excluding)
Fortios Fortinet 7.2.5 (including) 7.2.8 (excluding)
Fortios Fortinet 7.4.0 (including) 7.4.4 (excluding)

References