An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.
Source: MITRE
Published: 2022-05-04
Updated: 2022-07-12
Type: NVD-CWE-Other
Base Score: 5.5
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N
Impact Score: 4.9
Exploitability Score: 8
Severity: MEDIUM
Base Score: 5.4
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Impact Score: 2.5
Exploitability Score: 2.8
Severity: MEDIUM