cbcvebase.
CVE-2024-45327
published 2024-09-11

CVE-2024-45327: An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3…

high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetfortisoar
fortinetfortisoar>= 7.0.0 < 7.3.37.3.3
fortinetfortisoar7.0.0 – 7.0.3
fortinetfortisoar7.2.0 – 7.2.2
fortinetfortisoar7.3.0 – 7.3.2
fortinetfortisoar>= 7.4.0 < 7.4.47.4.4
fortinetfortisoar7.4.0 – 7.4.3