NA

CVE-2022-38377

Published: 25/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 2.7 | Impact Score: 1.4 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 up to and including 7.0.3, 6.4.0 up to and including 6.4.7, 6.2.0 up to and including 6.2.9, 6.0.0 up to and including 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 up to and including 7.0.3, 6.4.0 up to and including 6.4.8, 6.2.0 up to and including 6.2.10, 6.0.0 up to and including 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortimanager

fortinet fortianalyzer

fortinet fortimanager 7.2.0

fortinet fortianalyzer 7.2.0