Executive brief
An improper authorization vulnerability in the SSL VPN web portal of Fortinet FortiOS and FortiProxy allows an unauthenticated remote attacker to modify the password of a portal user. This is achieved by sending specially crafted HTTP requests to the affected system.
Affected products
- Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8, 5.4.1 to 5.4.10
- Fortinet FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
Timeline
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-10: disclosed