vulnerability

Fortinet FortiAnalyzer: Improper Privilege Management (CVE-2022-26118)

Severity
7
CVSS
(AV:L/AC:L/Au:M/C:C/I:C/A:C)
Published
Jul 18, 2022
Added
Jul 27, 2022
Modified
Jan 28, 2025

Description

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.

Solutions

fortinet-fortianalyzer-upgrade-6_4_8fortinet-fortianalyzer-upgrade-7_0_4
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.