Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40963 | An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information. |
Solution
Please upgrade to FortiManager version 7.2.1 or above Please upgrade to FortiManager version 7.0.4 or above Please upgrade to FortiManager version 6.4.8 or above Please upgrade to FortiAnalyzer version 7.2.1 or above Please upgrade to FortiAnalyzer version 7.0.4 or above Please upgrade to FortiAnalyzer version 6.4.9 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-20-143 |
|
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:52:08.654Z
Reserved: 2022-08-16T14:17:48.479Z
Link: CVE-2022-38377
Updated: 2024-08-03T10:54:03.674Z
Status : Modified
Published: 2022-11-25T16:15:10.747
Modified: 2024-11-21T07:16:21.223
Link: CVE-2022-38377
No data.
OpenCVE Enrichment
No data.
EUVD