CVE-2022-38378 MEDIUM

CVE-2022-38378

Vendor Fortinet
Product FortiOS
Weakness CWE-269
Published February 16, 2023
Last update October 22, 2024

CVSS base score

4.0/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C

What the vulnerability does

01Description

An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.

Key dates

02Disclosure timeline

February 16, 2023 CVE published
October 22, 2024 Record updated