ZeroHour

CVE-2022-38378

CVSS 3.1
6.0 medium
EPSS
<1%p15
Published
()
Modified
Description

An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.

Vendors
fortinet
Products
fortiproxy, fortios
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.