CVE-2022-23443
published 2022-05-04CVE-2022-23443: An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.21%
64.8th percentile
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | 6.4.0 – 6.4.4 | — |
| fortinet | fortisoar | 7.0.0 – 7.0.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API dat...
vendor_fortinet·2022-05-04·CVSS 7.5
CVE-2022-23443 [HIGH] An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API dat...
FG-IR-22-041: An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API dat...
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
CVEs: CVE-2022-23443
CVSS: 7.5 (high)
Affected products: FortiSOAR, Fortinet
GHSA
GHSA-cj8v-3m6g-6r37: An improper access control in Fortinet FortiSOAR before 7
ghsa_unreviewed·2022-05-05
CVE-2022-23443 [HIGH] CWE-863 GHSA-cj8v-3m6g-6r37: An improper access control in Fortinet FortiSOAR before 7
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-04
Published