Lucene search

K
fortinetFortiGuard LabsFG-IR-22-055
HistoryAug 02, 2022 - 12:00 a.m.

FortiADC - Unverified password change over the GUI

2022-08-0200:00:00
FortiGuard Labs
www.fortiguard.com
22
fortiadc
password change
cwe-620
authenticated attacker
http request

EPSS

0.001

Percentile

21.9%

An unverified password change vulnerability [CWE-620] in FortiADC may allow an authenticated attacker to bypass the Old Password check in the password change form for the account the attacker is logged into or for others accounts except admin when the attacker has Read Write access on System via a crafted HTTP request .

EPSS

0.001

Percentile

21.9%

Related for FG-IR-22-055