An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-23-270 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: fortinet

Published: 2023-12-13T06:43:21.604Z

Updated: 2023-12-13T06:43:21.604Z

Reserved: 2023-08-30T13:42:39.546Z


Link: CVE-2023-41673

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-13T07:15:15.860

Modified: 2023-12-15T19:10:46.137


Link: CVE-2023-41673

JSON object: View

cve-icon Redhat Information

No data.

CWE