A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.
2025-05-28T08:15:20.043
2025-06-04T14:34:54.323
Analyzed
CVSSv3.1: 2.3 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortimanager | < 7.0.8 | Yes |
Application | fortinet | fortimanager | < 7.2.2 | Yes |