CVE-2022-26118

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fortinetfortianalyzer
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortianalyzer
6.2.0 ≤
𝑥
≤ 6.2.9
fortinetfortianalyzer
6.4.0 ≤
𝑥
< 6.4.8
fortinetfortianalyzer
7.0.0 ≤
𝑥
< 7.0.4
fortinetfortimanager
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortimanager
6.2.0 ≤
𝑥
≤ 6.2.9
fortinetfortimanager
6.4.0 ≤
𝑥
< 6.4.8
fortinetfortimanager
7.0.0 ≤
𝑥
< 7.0.4
𝑥
= Vulnerable software versions