An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiswitchmanager | — | Upgrade FortiSwitchManager to 7.2.2Upgrade to the latest version of FortiSwitchManagerUpgrade FortiSwitchManager to 7.0.2 | Sep 30, 2026 | Nov 1, 2022 |
| Fortios | — | Upgrade FortiOS to 7.0.8Upgrade to the latest version of FortiOSUpgrade FortiOS to 7.2.1 | Nov 7, 2022 | Nov 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub