CVE-2024-45326: Medium severity Fortinet FortiDeceptor vulnerability
An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with none privileges to perform operations on the central management appliance via crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45326?
CVE-2024-45326 has been classified as having a high severity due to its potential impact on access control.
How do I fix CVE-2024-45326?
To fix CVE-2024-45326, upgrade to FortiDeceptor version 6.0.1 or later.
What versions of FortiDeceptor are affected by CVE-2024-45326?
CVE-2024-45326 affects FortiDeceptor versions 5.3.3 and below, as well as 5.2.1 and earlier.
Who is impacted by CVE-2024-45326?
Authenticated users with no privileges on affected FortiDeceptor versions can exploit CVE-2024-45326.
What type of vulnerability is CVE-2024-45326?
CVE-2024-45326 is categorized as an Improper Access Control vulnerability.