cbcvebase.
CVE-2023-50181
published 2024-07-09

CVE-2023-50181: An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortiadc
fortinetfortiadc>= 6.0.0 < 7.2.57.2.5
fortinetfortiadc6.0.0 – 6.0.4
fortinetfortiadc6.1.0 – 6.1.6
fortinetfortiadc6.2.0 – 6.2.6
fortinetfortiadc7.0.0 – 7.0.5
fortinetfortiadc7.1.0 – 7.1.4
fortinetfortiadc7.2.0 – 7.2.4
fortinetfortiadc>= 7.4.0 < 7.4.27.4.2
fortinetfortiadc7.4.0 – 7.4.1
fortinetfortinet