An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.
References
History

Tue, 22 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2022-11-25T15:47:41.422Z

Updated: 2024-10-22T20:52:08.654Z

Reserved: 2022-08-16T14:17:48.479Z

Link: CVE-2022-38377

cve-icon Vulnrichment

Updated: 2024-08-03T10:54:03.674Z

cve-icon NVD

Status : Modified

Published: 2022-11-25T16:15:10.747

Modified: 2023-11-07T03:50:06.800

Link: CVE-2022-38377

cve-icon Redhat

No data.