FortiOS -- Read-Only users able to modify the Interface fields using the API
An improper access control [CWE-284] vulnerability in FortiOS may allow a remote authenticated read-only user to modify the interface settings via the API.
Affected ProductsFortiOS version 7.2.0
FortiOS version 7.0.0 through 7.0.7
Please upgrade to FortiOS version 7.2.1 or above
Please upgrade to FortiOS version 7.0.8 or above