6.7

CVE-2022-26118

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortianalyzer Version >= 6.0.0 <= 6.0.11
Fortinet ≫ Fortianalyzer Version >= 6.2.0 <= 6.2.9
Fortinet ≫ Fortianalyzer Version >= 6.4.0 < 6.4.8
Fortinet ≫ Fortianalyzer Version >= 7.0.0 < 7.0.4
Fortinet ≫ Fortimanager Version >= 6.0.0 <= 6.0.11
Fortinet ≫ Fortimanager Version >= 6.2.0 <= 6.2.9
Fortinet ≫ Fortimanager Version >= 6.4.0 < 6.4.8
Fortinet ≫ Fortimanager Version >= 7.0.0 < 7.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.184
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Fortinet 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://fortiguard.com/psirt/FG-IR-21-056
Patch
Vendor Advisory