No analysis available yet.
Vendor Solution
Please upgrade to FortiEDR Manager version 6.2.3 or above Please upgrade to FortiEDR Manager version 6.0.2 or above
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41439 | An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations. |
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-371 |
|
Fri, 20 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:fortinet:fortiedrmanager:*:*:*:*:*:*:*:* |
Tue, 10 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations. | |
| First Time appeared |
Fortinet
Fortinet fortiedrmanager |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:fortinet:fortiedrmanager:6.0.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiedrmanager:6.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiedrmanager:6.2.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortiedrmanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-10T16:01:31.689Z
Reserved: 2024-08-27T06:43:07.250Z
Link: CVE-2024-45323
Updated: 2024-09-10T16:01:26.610Z
Status : Analyzed
Published: 2024-09-10T15:15:18.420
Modified: 2024-09-20T16:23:51.397
Link: CVE-2024-45323
No data.
OpenCVE Enrichment
No data.
EUVD