An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-292 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: fortinet

Published: 2023-11-14T18:05:48.807Z

Updated: 2023-11-14T18:05:48.807Z

Reserved: 2023-02-20T15:09:20.635Z


Link: CVE-2023-26205

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-14T18:15:28.260

Modified: 2023-11-20T17:58:52.160


Link: CVE-2023-26205

JSON object: View

cve-icon Redhat Information

No data.

CWE