Unauthorized modification of global threat feeds

Summary

A missing authorization [CWE-862] vulnerability in FortiManager may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.

Version Affected Solution
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 Not affected Not Applicable
FortiManager 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiManager 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above
FortiManager 6.4 Not affected Not Applicable

Timeline

2025-05-13: Initial publication