CVE-2024-45329
A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view un
Description
A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device information via key modification in API requests.
Weakness: CWE-639
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPortal | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiPortal
Credit
Fortinet is pleased to thank Pablo Castillo Andreu and Antonio Moreno from Telefonica Tech for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiPortal version 7.4.1 or above Please upgrade to FortiPortal version 7.2.6 or above Please upgrade to FortiPortal version 7.0.9 or above