Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5q5-qr9g-74ch

Опубликовано: 13 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.

EPSS

Процентиль: 34%
0.00141
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-620

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость программного средства для централизованного управления устройствами Fortinet FortiManager и межсетевого экрана FortiAnalyzer, связанная с отсутствием необходимой проверки при изменении пароля, позволяющая нарушителю изменять пароли администратора

EPSS

Процентиль: 34%
0.00141
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-620