CVE-2024-23112

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy vers

Severity
High 7.2
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.007
49.9th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 12, 2024
Assigned by fortinet

Description

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.

Weakness: CWE-639

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Check your version Firewall / NGFW cna-assigner
Fortinet FortiProxy Check your version SASE / SSE / Secure Web cna-assigner
Vendor-reported products (9)
  • Fortinet · FortiOS
  • Fortinet · FortiProxy
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortiproxy
  • fortinet · fortiproxy
  • fortinet · fortiproxy

Credit

Internally discovered and reported by Kai Ni from Burnaby InfoSec team.

Vendor remediation

Please upgrade to FortiOS version 7.4.2 or above Please upgrade to FortiOS version 7.2.7 or above Please upgrade to FortiOS version 7.0.14 or above Please upgrade to FortiOS version 6.4.15 or above Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.15 or above

Something wrong here?