Inadequate user validation and no brute force protection on change password requests

Summary

An improper authorization vulnerability [CWE-285] in FortiSOAR change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.

Version Affected Solution
FortiSOAR on-premise 7.6 Not affected Not Applicable
FortiSOAR on-premise 7.5 Not affected Not Applicable
FortiSOAR on-premise 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiSOAR on-premise 7.3 7.3.0 through 7.3.2 Upgrade to 7.3.3 or above
FortiSOAR on-premise 7.2 7.2 all versions Migrate to a fixed release
FortiSOAR on-premise 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank James Cato from New Zealand Police for reporting this vulnerability under responsible disclosure.

Timeline

2024-09-10: Initial publication
2024-09-11: Fix CVE name