Description
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-30685 | A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-056 |
|
History
Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-25T13:30:41.578Z
Reserved: 2022-02-25T00:00:00.000Z
Link: CVE-2022-26118
Updated: 2024-08-03T04:56:37.796Z
Status : Modified
Published: 2022-07-18T18:15:09.070
Modified: 2024-11-21T06:53:28.007
Link: CVE-2022-26118
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD