FG-IR-23-187: Unprivileged user can access web console and run some unauthorized commands
A client-side enforcement of server-side security [CWE-602] vulnerability in FortiManager and FortiAnalyzer may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-187?
The severity of FG-IR-23-187 is critical due to the potential for unauthorized access to a privileged web console.
How do I fix FG-IR-23-187?
To fix FG-IR-23-187, upgrade FortiManager and FortiAnalyzer to the latest recommended versions such as 7.4.1 or 7.2.6 or any other applicable remedial version.
Which versions of FortiManager are affected by FG-IR-23-187?
Affected versions of FortiManager include versions prior to 7.0.10, 7.2.4, and those in the 6.x range.
Does FG-IR-23-187 affect FortiAnalyzer?
Yes, FG-IR-23-187 affects certain versions of FortiAnalyzer, specifically those below 7.2.6.
What type of attack is possible with FG-IR-23-187?
FG-IR-23-187 may allow a remote attacker to execute client-side code leading to unauthorized access.