CVE-2023-25605

Severity
7.2HIGH
EPSS
0.1%
top 71.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7

Description

A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/fortisoar7.3.07.3.2
CVEListV5fortinet/fortisoar7.3.07.3.1

🔴Vulnerability Details

2
CVEList
CVE-2023-25605: A improper access control vulnerability in Fortinet FortiSOAR 72023-03-07
GHSA
GHSA-5g8q-j9fm-xvhf: A improper access control vulnerability in Fortinet FortiSOAR 72023-03-07

📋Vendor Advisories

1
Fortinet
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the admi...2023-03-07
CVE-2023-25605 (HIGH CVSS 7.2) | A improper access control vulnerabi | cvebase.io