Improper access control in FortiManager - CVE-2023-36554
Published: March 14, 2024
FortiManager
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in FortiWLM MEA within the backup and restore features. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.