Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-26118


A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.


Published

2022-07-18T18:15:09.070

Last Modified

2024-11-21T06:53:28.007

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortianalyzer ≤ 6.0.11 Yes
Application fortinet fortianalyzer ≤ 6.2.9 Yes
Application fortinet fortianalyzer < 6.4.8 Yes
Application fortinet fortianalyzer < 7.0.4 Yes
Application fortinet fortimanager ≤ 6.0.11 Yes
Application fortinet fortimanager ≤ 6.2.9 Yes
Application fortinet fortimanager < 6.4.8 Yes
Application fortinet fortimanager < 7.0.4 Yes

References