CVE-2023-41679: Improper inter ADOM access control
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs
Other sources
An improper access control vulnerability [CWE-284] in FortiManager management interface may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41679?
CVE-2023-41679 is an improper access control vulnerability in FortiManager management interface.
How does CVE-2023-41679 impact FortiManager?
CVE-2023-41679 may allow a remote and authenticated attacker with at least 'device management' permission to bypass access controls.
What is the severity of CVE-2023-41679?
CVE-2023-41679 has a severity rating of 9.6 (Critical).
Which versions of FortiManager are affected by CVE-2023-41679?
FortiManager versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2, and 6.0.0 through 6.0.12 are affected by CVE-2023-41679.
How can I fix CVE-2023-41679?
Apply the necessary patches or updates provided by Fortinet to fix CVE-2023-41679.