← back
CVE-2022-38377

CVE-2022-38377

CVSS 4.1 MEDIUMEPSS 0.5%CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →