Impact
The flaw is an improper authentication handling that lets an attacker generate random credentials and gain access to the FortiWeb GUI or CLI. This effectively bypasses authentication and grants unauthorized privileged access, potentially allowing full configuration changes and data exfiltration.
Affected Systems
Affected FortiWeb versions are 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, 7.2.0 through 7.2.12, and 7.0.0 through 7.0.12. All firmware releases in these ranges are compromised if the default login service is reachable.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity. The EPSS score is not available, so the precise likelihood of exploitation remains uncertain but the risk is significant. The vulnerability is not listed in the CISA KEV catalog, though the lack of a KEV listing does not reduce the impact. Attackers can exploit the weakness remotely over the network, and no special privileges or local access are required, indicating a low upfront effort.
OpenCVE Enrichment