CVE-2023-36638
Estado: ModificadaMedia (4.3)—
An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-284
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-36638",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-36638",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-24T19:45:02.088434Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@fortinet.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@fortinet.com",
"affectedData": [
{
"vendor": "Fortinet",
"product": "FortiManager",
"versions": [
{
"status": "affected",
"version": "7.2.0",
"versionType": "semver",
"lessThanOrEqual": "7.2.2"
},
{
"status": "affected",
"version": "7.0.0",
"versionType": "semver",
"lessThanOrEqual": "7.0.7"
},
{
"status": "affected",
"version": "6.4.0",
"versionType": "semver",
"lessThanOrEqual": "6.4.11"
},
{
"status": "affected",
"version": "6.2.0",
"versionType": "semver",
"lessThanOrEqual": "6.2.11"
},
{
"status": "affected",
"version": "6.0.0",
"versionType": "semver",
"lessThanOrEqual": "6.0.12"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Fortinet",
"product": "FortiAnalyzer",
"versions": [
{
"status": "affected",
"version": "7.2.0",
"versionType": "semver",
"lessThanOrEqual": "7.2.2"
},
{
"status": "affected",
"version": "7.0.0",
"versionType": "semver",
"lessThanOrEqual": "7.0.7"
},
{
"status": "affected",
"version": "6.4.0",
"versionType": "semver",
"lessThanOrEqual": "6.4.11"
},
{
"status": "affected",
"version": "6.2.0",
"versionType": "semver",
"lessThanOrEqual": "6.2.11"
},
{
"status": "affected",
"version": "6.0.0",
"versionType": "semver",
"lessThanOrEqual": "6.0.12"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-09-13T13:15:09.033",
"references": [
{
"url": "https://fortiguard.com/psirt/FG-IR-22-522",
"tags": [
"Vendor Advisory"
],
"source": "psirt@fortinet.com"
},
{
"url": "https://fortiguard.com/psirt/FG-IR-22-522",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@fortinet.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID."
},
{
"lang": "es",
"value": "Una vulnerabilidad de administración de privilegios inadecuada [CWE-269] en FortiManager 7.2.0 a 7.2.2, 7.0.0 a 7.0.7, 6.4.0 a 6.4.11, 6.2 todas las versiones, 6.0 todas las versiones y FortiAnalyzer 7.2.0 a 7.2 .2, 7.0.0 a 7.0.7, 6.4.0 a 6.4.11, 6.2 todas las versiones, 6.0 todas las versiones La API puede permitir que un usuario administrador de API remoto y autenticado acceda a algunas configuraciones del sistema, como la configuración del servidor de correo a través de la API a través de una ID de sesión de GUI robada."
}
],
"lastModified": "2026-06-17T06:06:43.417",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3279695-4C9A-4AB9-A3E3-81AD4AB189C7",
"versionEndExcluding": "6.4.12",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4EE403C3-3D66-4BF4-8D3C-1FCCD429EA28",
"versionEndExcluding": "7.0.8",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D074D55F-B03C-4D6C-91EF-AB74590164A5",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "7.2.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "142A4113-BEF9-4112-AC7D-757A18CFF2CF",
"versionEndExcluding": "6.4.12",
"versionStartIncluding": "6.4.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5248A7F-5122-4C07-8A4C-FE7A0BA07CF2",
"versionEndExcluding": "7.0.8",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98D47A3F-5A5B-4E5A-B145-2B1F9F29FC93",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "7.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@fortinet.com"
}