Improper access control on the central management appliance

Summary

An Improper Access Control vulnerability [CWE-284] in FortiDeceptor may allow an authenticated attacker with none privileges to perform operations on the central management appliance via crafted requests. 

Version Affected Solution
FortiDeceptor 6.1 Not affected Not Applicable
FortiDeceptor 6.0 6.0.0 Upgrade to 6.0.1 or above
FortiDeceptor 5.3 5.3 all versions Migrate to a fixed release
FortiDeceptor 5.2 5.2 all versions Migrate to a fixed release
FortiDeceptor 5.1 5.1 all versions Migrate to a fixed release
FortiDeceptor 5.0 5.0 all versions Migrate to a fixed release
FortiDeceptor 4.3 Not affected Not Applicable
FortiDeceptor 4.2 Not affected Not Applicable
FortiDeceptor 4.1 Not affected Not Applicable
FortiDeceptor 4.0 Not affected Not Applicable
FortiDeceptor 3.3 Not affected Not Applicable
FortiDeceptor 3.2 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Mister Thomas SAUTIER for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication