7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-40579 | An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. |
Solution
Please upgrade to FortiOS version 7.2.1 or above Please upgrade to FortiOS version 7.0.8 or above Please upgrade to FortiSwitchManager version 7.2.2 or above Please upgrade to FortiSwitchManager version 7.0.2 or above
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-22-174 |
![]() ![]() |
Thu, 26 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-26T14:17:39.335Z
Reserved: 2023-06-25T18:03:39.226Z
Link: CVE-2023-36635

Updated: 2024-08-02T16:52:54.065Z

Status : Modified
Published: 2023-09-07T13:15:08.433
Modified: 2024-11-21T08:10:08.487
Link: CVE-2023-36635

No data.

No data.