CVE-2024-23667
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to e
Severity
High 7.6
CVSS 3.1
Exploited
Not listed
EPSS
0.004
36.1th percentile
Discovered by
Not disclosed
Published
Jun 3, 2024
Assigned by fortinet
Description
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
Weakness: CWE-285
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb | Web & Application Security | cna-assigner |
Vendor-reported affected versions (6)
- Fortinet · FortiWebManager
- fortinet · fortiweb_manager
- fortinet · fortiweb_manager
- fortinet · fortiweb_manager
- fortinet · fortiweb_manager
- fortinet · fortiweb_manager
Vendor remediation
Upgrade to FortiWebManager version 7.4.0 or above Upgrade to FortiWebManager version 7.2.1 or above Upgrade to FortiWebManager version 7.0.5 or above Upgrade to FortiWebManager version 6.3.1 or above Upgrade to FortiWebManager version 6.2.5 or above