CVE-2023-36635
published 2023-09-07CVE-2023-36635: An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.38%
30.3th percentile
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2
7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | 7.0.0 – 7.0.1 | — |
| fortinet | fortiswitchmanager | 7.2.0 – 7.2.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Read-Only users able to add/modify the Interface fields using the API
vendor_fortinet·2022-11-02·CVSS 7.1
CVE-2022-38380 [MEDIUM] CWE-284 Read-Only users able to add/modify the Interface fields using the API
FG-IR-22-174: Read-Only users able to add/modify the Interface fields using the API
An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2
7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
CVEs: CVE-2022-38380, CVE-2023-36635
CWEs: CWE-284
CVSS: 7.1 (high)
Affected products: FortiOS, FortiSwitchManager, FortiSwitchmanager, Fortinet
GHSA
GHSA-h8ww-c8wr-cp22: An improper access control in Fortinet FortiSwitchManager version 7
ghsa_unreviewed·2023-09-07
CVE-2023-36635 [MEDIUM] CWE-284 GHSA-h8ww-c8wr-cp22: An improper access control in Fortinet FortiSwitchManager version 7
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2
7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-07
Published