Description
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
X
RC
X
Affected products
- fortinet / fortiextender7.4.0 – 7.4.2
- fortinet / fortiextender7.2.0 – 7.2.4
- fortinet / fortiextender7.0.0 – 7.0.4
References
- VENDOR_ADVISORYhttps://fortiguard.com/psirt/FG-IR-23-459