An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
2022-09-06T18:15:15.393
2024-11-21T07:02:31.513
Modified
CVSSv3.1: 7.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisoar | ≤ 6.4.4 | Yes |
Application | fortinet | fortisoar | < 7.0.3 | Yes |
Application | fortinet | fortisoar | 7.2.0 | Yes |