An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request.
2025-07-18T08:15:26.890
2025-07-22T17:08:39.680
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiisolator | ≤ 2.3.4 | Yes |
Application | fortinet | fortiisolator | < 2.4.5 | Yes |