First published: Tue Jun 25 2013(Updated: )
Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, modify, or delete the records of arbitrary users by leveraging the Guest role.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | <=5.0.2 | |
Fortinet FortiOS | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4604 has a medium severity level since it allows authenticated users to manipulate data of other users.
To fix CVE-2013-4604, upgrade FortiOS to version 5.0.3 or later.
CVE-2013-4604 affects Fortinet FortiGate devices running FortiOS versions prior to 5.0.3.
CVE-2013-4604 improperly restricts Guest role capabilities, allowing users to read, modify, or delete arbitrary records.
CVE-2013-4604 enables unauthorized data manipulation attacks by authenticated remote users.