FG-IR-24-023: Unauthorized modification of global threat feeds
A missing authorization [CWE-862] vulnerability in FortiManager may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-023?
The severity of FG-IR-24-023 is considered critical due to its potential to allow authenticated attackers to overwrite global threat feeds.
How do I fix FG-IR-24-023?
To fix FG-IR-24-023, upgrade FortiManager to version 7.2.2 or later if you are on versions between 7.2.0 and 7.2.1, or to version 7.0.8 or later if you are on versions between 7.0.0 and 7.0.7.
Who is affected by FG-IR-24-023?
FG-IR-24-023 affects users of FortiManager versions 7.2.0 to 7.2.1 and versions 7.0.0 to 7.0.7.
What type of attack does FG-IR-24-023 facilitate?
FG-IR-24-023 facilitates attacks where an authenticated user can exploit missing authorization to overwrite critical global threat feeds.
Is FG-IR-24-023 a new vulnerability?
FG-IR-24-023 is a recently identified vulnerability that exposes vulnerabilities in specific versions of FortiManager.