CVE-2022-38378

An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.0
v2 : unknown
v3 : 4.2
References () https://fortiguard.com/psirt/FG-IR-22-346 - Vendor Advisory () https://fortiguard.com/psirt/FG-IR-22-346 - Vendor Advisory

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands. An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.

Information

Published : 2023-02-16 19:15

Updated : 2024-11-21 07:16


NVD link : CVE-2022-38378

Mitre link : CVE-2022-38378

CVE.ORG link : CVE-2022-38378


JSON object : View

Products Affected

fortinet

  • fortiproxy
  • fortios
CWE
CWE-269

Improper Privilege Management