First published: Tue Jul 09 2024(Updated: )
An improper access control vulnerability [CWE-284] in FortiExtender authentication component may allow a remote authenticated attacker to create users with elevated privileges via a crafted HTTP request.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiExtender Firmware | >=7.4.0<=7.4.2 | |
Fortinet FortiExtender Firmware | >=7.2.0<=7.2.4 | |
Fortinet FortiExtender Firmware | >=7.0.0<=7.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-23-459 is classified based on the potential impact of improper access control vulnerabilities in FortiExtender.
To fix FG-IR-23-459, update your FortiExtender to version 7.4.3 or higher, 7.2.5 or higher, or 7.0.5 or higher depending on your current version.
FG-IR-23-459 affects multiple versions of FortiExtender, specifically versions from 7.0.0 to 7.4.2.
FG-IR-23-459 is an improper access control vulnerability, identified as CWE-284.
Organizations using FortiExtender versions that are within the affected ranges may be impacted by FG-IR-23-459.