CVE-2024-23667

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
03/06/2024
Last modified:
17/12/2024

Description

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiwebmanager:*:*:*:*:*:*:*:* 6.2.3 (including) 6.2.5 (excluding)
cpe:2.3:a:fortinet:fortiwebmanager:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.5 (excluding)
cpe:2.3:a:fortinet:fortiwebmanager:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwebmanager:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwebmanager:7.2.0:*:*:*:*:*:*:*