CVE-2022-27487: High severity fortinet fortideceptor vulnerability
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-27487.
What is the severity of CVE-2022-27487?
The severity of CVE-2022-27487 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2022-27487?
Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2, and versions before 3.2.3, as well as Fortinet FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2, and versions before 3.3.3 are affected.
How can this vulnerability be exploited?
A remote authenticated attacker can exploit CVE-2022-27487 by performing unauthorized API calls via crafted HTTP or HTTPS requests.
Is there a fix available for CVE-2022-27487?
Yes, Fortinet has released a fix for CVE-2022-27487. It is recommended to update to the latest patched version of FortiSandbox and FortiDeceptor.