CVE-2024-23665

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
03/06/2024
Last modified:
17/12/2024

Description

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 6.3.0 (including) 6.3.23 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.3 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.10 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.8 (excluding)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.3 (excluding)