Rapid7 Vulnerability & Exploit Database

Fortinet FortiAnalyzer: Unspecified Security Vulnerability (CVE-2023-36638)

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Fortinet FortiAnalyzer: Unspecified Security Vulnerability (CVE-2023-36638)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
09/13/2023
Created
09/20/2023
Added
09/20/2023
Modified
09/20/2023

Description

An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.

Solution(s)

  • fortinet-fortianalyzer-upgrade-6_4_12
  • fortinet-fortianalyzer-upgrade-7_0_8
  • fortinet-fortianalyzer-upgrade-7_2_3

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;