CVE-2024-23667

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to e

Severity
High 7.6
CVSS 3.1
Exploited
Not listed
EPSS
0.004
37.9th percentile
Discovered by
Third party
Vendor advisory field
Published
Jun 3, 2024
Assigned by fortinet

Description

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

Weakness: CWE-285

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported products (6)
  • Fortinet · FortiWebManager
  • fortinet · fortiweb_manager
  • fortinet · fortiweb_manager
  • fortinet · fortiweb_manager
  • fortinet · fortiweb_manager
  • fortinet · fortiweb_manager

Credit

Fortinet is pleased to thank security researchers Zach Hanley (@hacks_zach) of Horizon3.ai for discovering and reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiWebManager version 7.4.0 or above Upgrade to FortiWebManager version 7.2.1 or above Upgrade to FortiWebManager version 7.0.5 or above Upgrade to FortiWebManager version 6.3.1 or above Upgrade to FortiWebManager version 6.2.5 or above

Something wrong here?