Lucene search

K
fortinetFortiGuard LabsFG-IR-22-056
HistoryApr 11, 2023 - 12:00 a.m.

FortiSandbox / FortiDeceptor - Improper profile-based access control over APIs

2023-04-1100:00:00
FortiGuard Labs
www.fortiguard.com
11
fortisandbox
fortideceptor
vulnerability
api access control
http requests
https requests

0.002 Low

EPSS

Percentile

55.1%

An improper privilege management vulnerability [CWE-269] in FortiSandbox & FortiDeceptor may allow a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.

0.002 Low

EPSS

Percentile

55.1%

Related for FG-IR-22-056