CVE-2024-23669

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to e

Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.005
42.5th percentile
Discovered by
Not disclosed
Published
Jun 5, 2024
Assigned by fortinet

Description

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiWebManager
  • fortinet · fortiweb_manager

Vendor remediation

Upgrade to FortiWebManager version 7.4.0 or above Upgrade to FortiWebManager version 7.2.1 or above Upgrade to FortiWebManager version 7.0.5 or above Upgrade to FortiWebManager version 6.3.1 or above Upgrade to FortiWebManager version 6.2.5 or above