CVE-2023-46712: High severity fortinet fortiportal vulnerability
Published Jan 10, 2024
·Updated
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
Affected Software
2 affected components
Fortinet FortiPortal>=7.0.0<=7.0.6
Fortinet FortiPortal>=7.2.0<=7.2.1
Remediation
Information
Please upgrade to FortiPortal version 7.2.2
Please upgrade to FortiPortal version 7.0.7
Event History
Jan 10, 2024
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46712?
CVE-2023-46712 is considered a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2023-46712?
To fix CVE-2023-46712, upgrade Fortinet FortiPortal to version 7.0.7 or 7.2.2 or later.
3
What are the affected versions in CVE-2023-46712?
FortiPortal versions 7.0.0 through 7.0.6 and 7.2.0 through 7.2.1 are affected by CVE-2023-46712.
4
What type of attack does CVE-2023-46712 facilitate?
CVE-2023-46712 allows attackers to escalate their privileges through specially crafted HTTP requests.
5
Who is affected by CVE-2023-46712?
Organizations using affected versions of Fortinet FortiPortal may be vulnerable to CVE-2023-46712.