CVE-2022-30298
published 2022-09-06CVE-2022-30298: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | 6.4.0 – 6.4.4 | — |
| fortinet | fortisoar | >= 7.0.0 < 7.0.3 | 7.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has al...
vendor_fortinet·2022-09-06·CVSS 7.0
CVE-2022-30298 [HIGH] CWE-269 An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has al...
FG-IR-22-152: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has al...
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
CVEs: CVE-2022-30298
CWEs: CWE-269
CVSS: 7.0 (high)
Affected products: FortiSOAR, Fortinet
GHSA
GHSA-7mwv-v7fm-5jwc: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7
ghsa_unreviewed·2022-09-07
CVE-2022-30298 [HIGH] CWE-269 GHSA-7mwv-v7fm-5jwc: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-06
Published