CVE-2022-38377
EUVD-2022-4096325.11.2022, 16:15
An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortianalyzer | 6.0.0 ≤ 𝑥 ≤ 6.0.12 |
| fortinet | fortianalyzer | 6.2.0 ≤ 𝑥 ≤ 6.2.10 |
| fortinet | fortianalyzer | 6.4.0 ≤ 𝑥 ≤ 6.4.8 |
| fortinet | fortianalyzer | 7.0.0 ≤ 𝑥 ≤ 7.0.3 |
| fortinet | fortianalyzer | 7.2.0 |
| fortinet | fortimanager | 6.0.0 ≤ 𝑥 ≤ 6.0.11 |
| fortinet | fortimanager | 6.2.0 ≤ 𝑥 ≤ 6.2.9 |
| fortinet | fortimanager | 6.4.0 ≤ 𝑥 ≤ 6.4.7 |
| fortinet | fortimanager | 7.0.0 ≤ 𝑥 ≤ 7.0.3 |
| fortinet | fortimanager | 7.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration