Improper Privilege Management in FortiOS - CVE-2022-38378

 

Improper Privilege Management in FortiOS - CVE-2022-38378

Published: February 17, 2023


Vulnerability identifier: #VU72348
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38378
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the device.

The vulnerability exists due to improper privilege management. A remote administrative user with access to the admin profile section (System subsection Administrator Users) can modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.


Affected software

FortiOS
FortiProxy

How to mitigate CVE-2022-38378

Install updates from vendor's website.

FortiOS - addressed in versions 7.0.8, 7.2.1
FortiProxy - addressed in versions 7.0.8, 7.2.2

External References

Related Security Bulletins