2024-02-15 15:01:59 +00:00
{
"id" : "CVE-2023-45581" ,
"sourceIdentifier" : "psirt@fortinet.com" ,
"published" : "2024-02-15T14:15:45.033" ,
2024-02-20 21:00:35 +00:00
"lastModified" : "2024-02-20T20:54:47.437" ,
"vulnStatus" : "Analyzed" ,
2024-02-15 15:01:59 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an\u00a0Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests."
2024-02-20 21:00:35 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de administraci\u00f3n de privilegios inadecuada [CWE-269] en Fortinet FortiClientEMS versi\u00f3n 7.2.0 a 7.2.2 y anteriores a 7.0.10 permite a un administrador del sitio con privilegios de superadministrador realizar operaciones administrativas globales que afectan a otros sitios a trav\u00e9s de solicitudes HTTP o HTTPS manipuladas."
2024-02-15 15:01:59 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-02-20 21:00:35 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "HIGH" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.2 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.2 ,
"impactScore" : 5.9
} ,
2024-02-15 15:01:59 +00:00
{
"source" : "psirt@fortinet.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
2024-02-20 21:00:35 +00:00
"source" : "nvd@nist.gov" ,
2024-02-15 15:01:59 +00:00
"type" : "Primary" ,
2024-02-20 21:00:35 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
{
"source" : "psirt@fortinet.com" ,
"type" : "Secondary" ,
2024-02-15 15:01:59 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-269"
}
]
}
] ,
2024-02-20 21:00:35 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "7.0.10" ,
"matchCriteriaId" : "17D081E7-E4F0-4E0F-BEBF-BF3AD0641861"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "7.2.0" ,
"versionEndIncluding" : "7.2.2" ,
"matchCriteriaId" : "3C4BC53A-0E69-4CDE-B89A-E6AAC3ADB1E0"
}
]
}
]
}
] ,
2024-02-15 15:01:59 +00:00
"references" : [
{
"url" : "https://fortiguard.com/psirt/FG-IR-23-357" ,
2024-02-20 21:00:35 +00:00
"source" : "psirt@fortinet.com" ,
"tags" : [
"Vendor Advisory"
]
2024-02-15 15:01:59 +00:00
}
]
}