CVE Vulnerabilities

CVE-2024-45323

Published: Sep 10, 2024 | Modified: Sep 20, 2024
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.

Affected Software

Name Vendor Start Version End Version
Fortiedrmanager Fortinet 6.2.0 (including) 6.2.2 (excluding)
Fortiedrmanager Fortinet 6.0.1 (including) 6.0.1 (including)

References