Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8x4-gj4q-pwgq

Опубликовано: 08 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.

EPSS

Процентиль: 38%
0.00165
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.2
nvd
около 4 лет назад

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.

EPSS

Процентиль: 38%
0.00165
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863