FG-IR-23-472: Priviledged admin able to view device summary for device in different ADOM
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager Administrative Domain (ADOM) may allow a remote authenticated attacker assigned to an ADOM to access device summary of other ADOMs via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-472?
The severity of FG-IR-23-472 is categorized as critical due to the potential for unauthorized access to sensitive information in FortiManager.
How do I fix FG-IR-23-472?
To fix FG-IR-23-472, update FortiManager to versions 7.4.3 or 7.2.6 or later, as applicable.
Which versions of FortiManager are affected by FG-IR-23-472?
FortiManager versions 7.4.0 to 7.4.2 and 7.2.0 to 7.2.5 are affected by FG-IR-23-472.
Who can exploit FG-IR-23-472?
The FG-IR-23-472 vulnerability can be exploited by remote authenticated attackers assigned to an Administrative Domain (ADOM).
What type of vulnerability is FG-IR-23-472?
FG-IR-23-472 is classified as an exposure of sensitive information vulnerability, specifically categorized under CWE-200.