First published: Thu Feb 16 2023(Updated: )
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiProxy | >=1.1.0<=2.0.9 | |
Fortinet FortiProxy | >=7.0.0<7.0.8 | |
Fortinet FortiProxy | >=7.2.0<7.2.2 | |
Fortinet FortiOS | >=6.0.0<7.0.8 | |
Fortinet FortiOS | >=7.2.0<7.2.1 |
Please upgrade to FortiOS version 7.2.1 or above Please upgrade to FortiOS version 7.0.8 or above Please upgrade to FortiProxy version 7.2.2 or above Please upgrade to FortiProxy version 7.0.8 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-38378.
CVE-2022-38378 has a severity level of medium.
Fortinet FortiOS versions 7.2.0 and before 7.0.7, and FortiProxy versions 7.2.0 through 7.2.1 and before 7.0.7 are affected by CVE-2022-38378.
An attacker with access to the admin profile section in the System subsection Administrator Users can exploit CVE-2022-38378 to modify their own profile.
Yes, you can find more information about CVE-2022-38378 at the following reference: [FG-IR-22-346](https://fortiguard.com/psirt/FG-IR-22-346).