CVE-2024-32124

An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs v

Severity
Medium 4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
26.1th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jul 18, 2025
Assigned by fortinet

Description

An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiIsolator SASE / SSE / Secure Web cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiIsolator

Credit

Internally discovered and reported by Leslie Zhou of Fortinet Vulnerability Research team.

Vendor remediation

Please upgrade to FortiIsolator version 2.4.5 or above

Something wrong here?