CVE-2023-36638: Improper privilege management on API requests
An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
Other sources
An improper privilege management vulnerability [CWE-269] in FortiManager and FortiAnalyzer API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiManager and FortiAnalyzer vulnerability?
The vulnerability ID for this FortiManager and FortiAnalyzer vulnerability is CVE-2023-36638.
What is the severity of vulnerability CVE-2023-36638?
The severity rating of vulnerability CVE-2023-36638 is 4.3 (medium).
Which versions of FortiManager and FortiAnalyzer are affected by vulnerability CVE-2023-36638?
FortiManager versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, and 6.0 all versions, and FortiAnalyzer versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, and 6.0 all versions are affected by vulnerability CVE-2023-36638.
What is the CWE-ID associated with vulnerability CVE-2023-36638?
The CWE-ID associated with vulnerability CVE-2023-36638 is CWE-269 (Improper Privilege Management).
How can I fix vulnerability CVE-2023-36638 in FortiManager and FortiAnalyzer?
To fix vulnerability CVE-2023-36638 in FortiManager and FortiAnalyzer, it is recommended to update to the latest patched version provided by Fortinet.