An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-012 |
History
Thu, 22 Aug 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet
Fortinet fortios |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fortinet
Fortinet fortios |
Thu, 15 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 Aug 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system. | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2024-08-13T15:51:56.981Z
Updated: 2024-08-15T14:16:57.399Z
Reserved: 2024-05-29T08:44:50.759Z
Link: CVE-2024-36505
Vulnrichment
Updated: 2024-08-15T14:16:51.582Z
NVD
Status : Analyzed
Published: 2024-08-13T16:15:08.970
Modified: 2024-08-22T14:36:31.643
Link: CVE-2024-36505
Redhat
No data.