CVE-2022-38377

EUVD-2022-40963
An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
fortinetCNA
4.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Affected Products (NVD)
VendorProductVersion
fortinetfortianalyzer
6.0.0 ≤
𝑥
≤ 6.0.12
fortinetfortianalyzer
6.2.0 ≤
𝑥
≤ 6.2.10
fortinetfortianalyzer
6.4.0 ≤
𝑥
≤ 6.4.8
fortinetfortianalyzer
7.0.0 ≤
𝑥
≤ 7.0.3
fortinetfortianalyzer
7.2.0
fortinetfortimanager
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortimanager
6.2.0 ≤
𝑥
≤ 6.2.9
fortinetfortimanager
6.4.0 ≤
𝑥
≤ 6.4.7
fortinetfortimanager
7.0.0 ≤
𝑥
≤ 7.0.3
fortinetfortimanager
7.2.0
𝑥
= Vulnerable software versions