Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-36638


An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.


Published

2023-09-13T13:15:09.033

Last Modified

2024-11-21T08:10:08.903

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortianalyzer < 6.4.12 Yes
Application fortinet fortianalyzer < 7.0.8 Yes
Application fortinet fortianalyzer < 7.2.3 Yes
Application fortinet fortimanager < 6.4.12 Yes
Application fortinet fortimanager < 7.0.8 Yes
Application fortinet fortimanager < 7.2.3 Yes

References