Back

MEDIUM

An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2

Published Sep 7, 2023

Description

An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.

Affected products

Remediation

Vendor solution

Please upgrade to FortiOS version 7.2.1 or above Please upgrade to FortiOS version 7.0.8 or above Please upgrade to FortiSwitchManager version 7.2.2 or above Please upgrade to FortiSwitchManager version 7.0.2 or above

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published Sep 7, 2023
Updated Sep 26, 2024
Reserved Jun 25, 2023
CISA Vulnrichment
Updated Sep 26, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a