Improper access control vulnerability in administrative interface

Summary

An improper access control vulnerability [CWE-284] in FortiADC may allow a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiADC 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.2 or above
FortiADC 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiADC 7.1 7.1 all versions Migrate to a fixed release
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 6.2 all versions Migrate to a fixed release
FortiADC 6.1 6.1 all versions Migrate to a fixed release
FortiADC 6.0 6.0 all versions Migrate to a fixed release
FortiADC 5.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Theo Leleu of Fortinet Product Security team.

Timeline

2024-07-09: Initial publication