Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18533
HistoryMar 03, 2022 - 12:00 a.m.

Fortinet FortiAnalyzer Privilege Licensing and Access Control Issues Vulnerability

2022-03-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
fortinet
fortianalyzer
access control
vulnerability
network security
reporting suite
unauthorized access
password change

EPSS

0.001

Percentile

42.8%

Fortinet FortiAnalyzer is a centralized network security reporting solution from Fortinet (USA). The product is used to collect network log data and analyze, report, and archive security events, network traffic, and Web content in the logs through the reporting suite.Fortinet FortiAnalyzer is vulnerable to an access control error that results from a network system or product not properly restricting access to resources from unauthorized roles. An attacker could use this vulnerability to bypass device policies and force its users to perform a password change operation.

EPSS

0.001

Percentile

42.8%

Related for CNVD-2022-18533