Improper access control in backup and restore features
Summary
An improper access control vulnerability [`CWE-284]` in FortiWLM MEA for FortiManager may allow an unauthenticated remote attacker to execute arbitrary code or commands via specifically crafted requests.
Note that FortiWLM MEA is not installed by default on FortiManager and can be disabled as a workaround.
| Version | Affected | Solution |
|---|---|---|
| FortiManager 7.4 | 7.4.0 | Upgrade to 7.4.1 or above |
| FortiManager 7.2 | 7.2.0 through 7.2.3 | Upgrade to 7.2.4 or above |
| FortiManager 7.0 | 7.0.0 through 7.0.10 | Upgrade to 7.0.11 or above |
| FortiManager 6.4 | 6.4.0 through 6.4.13 | Upgrade to 6.4.14 or above |
| FortiManager 6.2 | 6.2 all versions | Migrate to a fixed release |
Acknowledgement
Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.Timeline
2024-02-22: Initial publication2025-01-27: Move to solutions table display