Lucene search

K
cveFortinetCVE-2022-26118
HistoryJul 18, 2022 - 6:15 p.m.

CVE-2022-26118

2022-07-1818:15:09
CWE-269
fortinet
web.nvd.nist.gov
48
6
cve-2022-26118
cwe-268
fortimanager
fortianalyzer
privilege escalation
incorrect permissions
nvd

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.

Affected configurations

Nvd
Node
fortinetfortianalyzerRange6.0.06.0.11
OR
fortinetfortianalyzerRange6.2.06.2.9
OR
fortinetfortianalyzerRange6.4.06.4.8
OR
fortinetfortianalyzerRange7.0.07.0.4
OR
fortinetfortimanagerRange6.0.06.0.11
OR
fortinetfortimanagerRange6.2.06.2.9
OR
fortinetfortimanagerRange6.4.06.4.8
OR
fortinetfortimanagerRange7.0.07.0.4
VendorProductVersionCPE
fortinetfortianalyzer*cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
fortinetfortimanager*cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiManager , FortiAnalyzer",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiManager 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3; FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3"
      }
    ]
  }
]

Social References

More

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for CVE-2022-26118