CVE-2022-26118
published 2022-07-18CVE-2022-26118: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.26%
17.2th percentile
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.0.0 – 6.0.11 | — |
| fortinet | fortianalyzer | 6.2.0 – 6.2.9 | — |
| fortinet | fortianalyzer | >= 6.4.0 < 6.4.8 | 6.4.8 |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.4 | 7.0.4 |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 6.0.0 – 6.0.11 | — |
| fortinet | fortimanager | 6.2.0 – 6.2.9 | — |
| fortinet | fortimanager | >= 6.4.0 < 6.4.8 | 6.4.8 |
| fortinet | fortimanager | >= 7.0.0 < 7.0.4 | 7.0.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0...
vendor_fortinet·2022-07-18·CVSS 6.7
CVE-2022-26118 [MEDIUM] CWE-269 A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0...
FG-IR-21-056: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0...
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
CVEs: CVE-2022-26118
CWEs: CWE-269
CVSS: 6.7 (medium)
Affected products: FortiAnalyzer, FortiManager
GHSA
GHSA-825g-6mc8-89vv: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6
ghsa_unreviewed·2022-07-19
CVE-2022-26118 [MEDIUM] CWE-269 GHSA-825g-6mc8-89vv: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-18
Published