First published: Tue Mar 07 2023(Updated: )
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSOAR Imap Connector | >=7.3.0<7.3.2 |
Please upgrade to FortiSOAR version 7.3.2 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25605 is classified as a high-severity vulnerability due to its potential to allow unauthorized actions by authenticated users.
To fix CVE-2023-25605, upgrade Fortinet FortiSOAR to version 7.3.2 or later to mitigate the improper access control.
Exploiting CVE-2023-25605 can allow an authenticated attacker to perform unauthorized administrative actions via crafted HTTP requests.
CVE-2023-25605 affects users of Fortinet FortiSOAR versions 7.3.0 and 7.3.1.
There are no official workarounds for CVE-2023-25605; updating the software is the recommended course of action.