cbcvebase.
CVE-2022-23443
published 2022-05-04

CVE-2022-23443: An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortinet_fortisoar
fortinetfortisoar
fortinetfortisoar
fortinetfortisoar6.4.0 – 6.4.4
fortinetfortisoar7.0.0 – 7.0.2