CVE-2022-38378: Medium severity fortinet fortiproxy ssl vpn webmode vulnerability
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-38378.
What is the severity level of CVE-2022-38378?
CVE-2022-38378 has a severity level of medium.
Which software versions are affected by CVE-2022-38378?
Fortinet FortiOS versions 7.2.0 and before 7.0.7, and FortiProxy versions 7.2.0 through 7.2.1 and before 7.0.7 are affected by CVE-2022-38378.
How can an attacker exploit CVE-2022-38378?
An attacker with access to the admin profile section in the System subsection Administrator Users can exploit CVE-2022-38378 to modify their own profile.
Are there any references available for more information about CVE-2022-38378?
Yes, you can find more information about CVE-2022-38378 at the following reference: [FG-IR-22-346](https://fortiguard.com/psirt/FG-IR-22-346).