← Back

CVE-2024-36505

nvd nist
Published: Aug 13, 2024Modified: Aug 22, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.

Affected (4)

Products: Fortinet: Fortios
1 product
Fortios
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.13 to 6.4.15
From 7.0.12 to 7.0.15
From 7.2.5 to 7.2.8
From 7.4.0 to 7.4.4

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.