CVE-2022-38380

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/11/2022
Last modified:
04/11/2022

Description

An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.7 (including)
cpe:2.3:o:fortinet:fortios:7.2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools