CVE-2023-50181

Severity
6.5MEDIUM
EPSS
0.2%
top 63.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 9

Description

An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/fortiadc6.0.07.2.5+1
CVEListV5fortinet/fortiadc7.4.07.4.1+6

🔴Vulnerability Details

2
GHSA
GHSA-c85c-x2rg-634r: An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 72024-07-09
CVEList
CVE-2023-50181: An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 72024-07-09

📋Vendor Advisories

1
Fortinet
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 al...2024-07-09
CVE-2023-50181 (MEDIUM CVSS 6.5) | An improper access control vulnerab | cvebase.io