FortiADC - Unverified password change over the GUI

Summary

An unverified password change vulnerability [CWE-620] in FortiADC may allow an authenticated attacker to bypass the Old Password check in the password change form for the account the attacker is logged into or for others accounts except `admin` when the attacker has Read Write access on System via a crafted HTTP request .

Affected Products

At least
FortiADC version 6.2.0 through 6.2.3
FortiADC version 6.1.0 through 6.1.6
FortiADC version 6.0.0 through 6.0.4
FortiADC version 5.4.0 through 5.4.5
FortiADC version 5.3.0 through 5.3.7
FortiADC version 5.2.0 through 5.2.8
FortiADC version 5.1.0 through 5.1.7
FortiADC version 5.0.0 through 5.0.4

Solutions

Please upgrade to FortiADC version 7.0.0 or above,

Please upgrade to FortiADC version 6.2.4 or above.

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.