PT-2023-6007 · Fortinet · Fortimanager

CVE-2023-41679

·

Publicado

2023-10-10

·

Atualizado

2023-10-13

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiManager versions 6.0 through 7.2.2
Description The issue is related to improper access control in the FortiManager management interface. This can allow a remote and authenticated attacker with at least "device management" permission on their profile and belonging to a specific ADOM to add and delete CLI scripts on other ADOMs.
Recommendations For FortiManager versions 6.0 through 7.2.2, consider restricting access to the management interface to minimize the risk of exploitation. As a temporary workaround, limit the "device management" permission to only necessary profiles and ADOMs until a patch is available. Restrict the ability to add and delete CLI scripts on other ADOMs to prevent unauthorized changes.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06708
CVE-2023-41679

Produtos afetados

Fortimanager