Lucene search

K
nvd[email protected]NVD:CVE-2022-30298
HistorySep 06, 2022 - 6:15 p.m.

CVE-2022-30298

2022-09-0618:15:15
CWE-269
web.nvd.nist.gov
3
fortinet fortisoar
privilege management
arbitrary python commands

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.

Affected configurations

Nvd
Node
fortinetfortisoarRange6.4.06.4.4
OR
fortinetfortisoarRange7.0.07.0.3
OR
fortinetfortisoarMatch7.2.0
VendorProductVersionCPE
fortinetfortisoar*cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*
fortinetfortisoar7.2.0cpe:2.3:a:fortinet:fortisoar:7.2.0:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2022-30298