CVE-2024-32124

An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs v

Severity
Medium 4
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.003
23.6th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jul 18, 2025
Assigned by fortinet

Description

An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiIsolator SASE / SSE / Secure Web cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiIsolator

Credit

Internally discovered and reported by Leslie Zhou of Fortinet Vulnerability Research team.

Vendor remediation

Please upgrade to FortiIsolator version 2.4.5 or above

Something wrong here?