« Volver al listado

CVE-2024-45323

Estado: AnalizadaBaja (2.7)—

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45323",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45323",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-10T15:59:27.913308Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@fortinet.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@fortinet.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:fortinet:fortiedrmanager:6.2.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:fortinet:fortiedrmanager:6.2.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:fortinet:fortiedrmanager:6.0.1:*:*:*:*:*:*:*"
          ],
          "vendor": "Fortinet",
          "product": "FortiEDR Manager",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.0",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.1"
            },
            {
              "status": "affected",
              "version": "6.0.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-10T15:15:18.420",
  "references": [
    {
      "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-371",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@fortinet.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@fortinet.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de control de acceso indebido [CWE-284] en FortiEDR Manager API 6.2.0 a 6.2.2, 6.0 todas las versiones puede permitir, en un contexto de entorno compartido, que un administrador autenticado con permisos de API REST en su perfil y restringido a una organización específica acceda a registros de backend que incluyen información relacionada con otras organizaciones."
    }
  ],
  "lastModified": "2026-06-17T07:54:01.610",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fortinet:fortiedrmanager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D55CFC12-7AC0-42DA-83E0-67105284351C",
              "versionEndExcluding": "6.2.2",
              "versionStartIncluding": "6.2.0"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiedrmanager:6.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC599F7F-0FC8-4114-92FC-E19A9648A879"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@fortinet.com"
}