Fortinet FortiWeb - Stack based buffer overflow in SAML management (FG-IR-22-151)

high Nessus Plugin ID 171902

Version 1.2

Mar 1, 2023, 2:07 PM

  • CVSS metrics ("CVSSv2 score" changed from "7.7" to "9.0". "CVSSv2 score" changed from "7.7" to "9.0". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 score" changed from "8.0" to "8.8". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 score" changed from "8.0" to "8.8". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C")
  • CVSSv3 score source (set to "CVE-2023-23781")

Plugin Feed: 202303011407

Version 1.1

Feb 27, 2023, 2:07 PM

  • CVSS metrics ("CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:H/Au:M/C:C/I:C/A:C" to "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv3 score" changed from "6.4" to "8.0". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:H/Au:M/C:C/I:C/A:C" to "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv3 score" changed from "6.4" to "8.0". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:H/Au:M/C:C/I:C/A:C" to "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv3 score" changed from "6.4" to "8.0")
  • CVSSv2 severity (based on CVE-2023-23781, severity increased from "Medium" to "High")
  • CVSSv3 score source (set to "CVE-2023-23781")
  • CVSSv3 severity (based on CVE-2023-23781, severity increased from "Medium" to "High")

Plugin Feed: 202302271407

Version 1.0

Feb 24, 2023, 6:03 PM

  • New

Plugin Feed: 202302241803

* Changelogs are generally available for changes made after Nov 1, 2022