CVE-2024-23112

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy vers

Severity
High 7.2
CVSS 3.1
Exploited
Not listed
EPSS
0.007
50.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 12, 2024
Assigned by fortinet

Description

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.

Weakness: CWE-639

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Vendor-reported products (9)
  • Fortinet · FortiOS
  • Fortinet · FortiProxy
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortiproxy
  • fortinet · fortiproxy
  • fortinet · fortiproxy

Credit

Internally discovered and reported by Kai Ni from Burnaby InfoSec team.

Vendor remediation

Please upgrade to FortiOS version 7.4.2 or above Please upgrade to FortiOS version 7.2.7 or above Please upgrade to FortiOS version 7.0.14 or above Please upgrade to FortiOS version 6.4.15 or above Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.15 or above

Something wrong here?