Improper access control in backup and restore features

Summary

An improper access control vulnerability [`CWE-284]` in FortiWLM MEA for FortiManager may allow an unauthenticated remote attacker to execute arbitrary code or commands via specifically crafted requests.

Note that FortiWLM MEA is not installed by default on FortiManager and can be disabled as a workaround.

Version Affected Solution
FortiManager 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiManager 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiManager 7.0 7.0.0 through 7.0.10 Upgrade to 7.0.11 or above
FortiManager 6.4 6.4.0 through 6.4.13 Upgrade to 6.4.14 or above
FortiManager 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2024-02-22: Initial publication
2025-01-27: Move to solutions table display