CVE-2024-45327

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenti

Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.003
27.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Sep 11, 2024
Assigned by fortinet

Description

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.

Weakness: CWE-307

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSOAR

Credit

Fortinet is pleased to thank James Cato from New Zealand Police for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiSOAR version 7.5.0 or above Please upgrade to FortiSOAR version 7.4.4 or above Please upgrade to FortiSOAR version 7.3.3 or above

Something wrong here?