CVE-2023-46717: Improper authentication following read-only user login
An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.
Other sources
An improper authentication vulnerability [CWE-287] in FortiOS when configured with FortiAuthenticator in HA may allow an authenticated attacker with at least read-only permission to gain read-write access via successive login attempts.
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-46717?
CVE-2023-46717 is classified as a high severity vulnerability due to its potential to allow unauthorized read-write access.
How do I fix CVE-2023-46717?
To fix CVE-2023-46717, upgrade FortiOS to versions 7.0.13, 7.2.7, or 7.4.2 or above.
What systems are affected by CVE-2023-46717?
CVE-2023-46717 affects FortiOS versions 7.4.1 and below, 7.2.6 and below, and 7.0.12 and below when configured with FortiAuthenticator in HA.
What type of vulnerability is CVE-2023-46717?
CVE-2023-46717 is an improper authentication vulnerability categorized under CWE-287.
Can a readonly user escalate privileges due to CVE-2023-46717?
Yes, a readonly user may gain unauthorized read-write access through repeated login attempts due to CVE-2023-46717.