Lucene search

K
cvelistFortinetCVELIST:CVE-2022-26121
HistoryOct 10, 2022 - 12:00 a.m.

CVE-2022-26121

2022-10-1000:00:00
fortinet
www.cve.org
6
cve-2022-26121
cwe-668
fortianalyzer
fortimanager
unauthenticated access
remote attacker
url path

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

48.1%

An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

48.1%

Related for CVELIST:CVE-2022-26121