** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token values.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48611 | ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token values. |
Fixes
Solution
This product is end of life and no longer supported. Please consider replacing with an equivalent FortiGate appliance as approriate.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-061 |
|
History
No history.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T19:59:52.074Z
Reserved: 2023-09-27T12:26:48.750Z
Link: CVE-2023-44252
No data.
Status : Modified
Published: 2023-12-13T09:15:34.473
Modified: 2024-11-21T08:25:31.487
Link: CVE-2023-44252
No data.
OpenCVE Enrichment
No data.
EUVD