{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-23665","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2024-01-19T08:23:28.612Z","datePublished":"2024-06-03T09:50:33.614Z","dateUpdated":"2024-08-01T23:06:25.362Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiWeb","defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"7.4.0","lessThanOrEqual":"7.4.2","status":"affected"},{"versionType":"semver","version":"7.2.0","lessThanOrEqual":"7.2.7","status":"affected"},{"versionType":"semver","version":"7.0.0","lessThanOrEqual":"7.0.10","status":"affected"},{"versionType":"semver","version":"6.4.0","lessThanOrEqual":"6.4.3","status":"affected"},{"versionType":"semver","version":"6.3.0","lessThanOrEqual":"6.3.23","status":"affected"}]}],"descriptions":[{"lang":"en","value":"Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2024-06-03T09:50:33.614Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-285","description":"Improper access control","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N/E:P/RL:X/RC:C"}}],"solutions":[{"lang":"en","value":"Please upgrade to FortiWeb version 7.4.3 or above \nPlease upgrade to FortiWeb version 7.2.8 or above \n"}],"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-23-474","url":"https://fortiguard.fortinet.com/psirt/FG-IR-23-474"}]},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-23665","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-06-03T13:39:32.057887Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:46:07.306Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T23:06:25.362Z"},"title":"CVE Program Container","references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-23-474","url":"https://fortiguard.fortinet.com/psirt/FG-IR-23-474","tags":["x_transferred"]}]}]}}