An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.
Una vulnerabilidad de activo interno expuesto a nivel o estado de acceso de depuración inseguro [CWE-1244] vulnerabilidad en Fortinet FortiOS 7.6.0 hasta 7.6.2, FortiOS 7.4.0 hasta 7.4.7, FortiOS 7.2.0 hasta 7.2.10, FortiOS 7.0.0 hasta 7.0.16, FortiOS 6.4 todas las versiones, FortiProxy 7.6.0 hasta 7.6.3, FortiProxy 7.4.0 hasta 7.4.10, FortiProxy 7.2.0 hasta 7.2.14, FortiProxy 7.0 todas las versiones puede permitir a un administrador autenticado ejecutar scripts lua mediante comandos CLI manipulados.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-1244
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| fortinet | fortios | * | <built-in method update of dict object at 0x763e95a15e40> | Operating System |
| fortinet | fortios | * | <built-in method update of dict object at 0x763f1c44c540> | Operating System |
| fortinet | fortios | * | <built-in method update of dict object at 0x763f1c44d7c0> | Operating System |
| fortinet | fortios | * | <built-in method update of dict object at 0x763f1c44f940> | Operating System |
| fortinet | fortios | * | <built-in method update of dict object at 0x763e95a15f80> | Operating System |
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x763e95a172c0> | Application |
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x763f1c44ff00> | Application |
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x763f1c4ce840> | Application |
| fortinet | fortiproxy | * | <built-in method update of dict object at 0x763ef6ea9600> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |