CVE-2024-45323: Medium severity fortinet fortimanager vulnerability
An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45323?
CVE-2024-45323 is categorized as a critical vulnerability due to its potential impact on access control in the FortiEDR Manager API.
How do I fix CVE-2024-45323?
To mitigate CVE-2024-45323, it is recommended to update FortiEDR Manager to the latest version that addresses the improper access control issues.
What systems are affected by CVE-2024-45323?
CVE-2024-45323 affects FortiEDR Manager versions 6.2.0 to 6.2.2 and all versions of 6.0, including 6.0.1.
What is the nature of the vulnerability in CVE-2024-45323?
CVE-2024-45323 is an improper access control vulnerability that allows unauthorized access to sensitive backend logs.
Who is impacted by CVE-2024-45323?
Administrators with REST API permissions restricted to a specific organization in shared environments may be impacted by CVE-2024-45323.