<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Unverified password change over the GUI</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-055</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2022-08-02T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2022-08-02T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2022-08-02T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An unverified password change vulnerability [CWE-620] in FortiADC may allow an authenticated attacker to bypass the Old Password check in the password change form for the account the attacker is logged into or for others accounts except admin when the attacker has Read Write access on System via a crafted HTTP request .
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            At leastFortiADC 7.1 all versions are not affectedFortiADC 7.0 all versions are not affectedFortiADC version 6.2.0 through 6.2.3FortiADC 6.1 all versionsFortiADC 6.0 all versionsFortiADC 5.4 all versionsFortiADC 5.3 all versionsFortiADC 5.2 all versionsFortiADC 5.1 all versionsFortiADC 5.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiADC version 7.0.0 or above,Please upgrade to FortiADC version 6.2.4 or above.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Théo Leleu of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiADC" Type="Product Name">
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.3">FortiADC 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.2">FortiADC 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.1">FortiADC 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.0">FortiADC 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.1.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.6">FortiADC 6.1.6</FullProductName>
                </Branch>
                <Branch Name="6.1.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.5">FortiADC 6.1.5</FullProductName>
                </Branch>
                <Branch Name="6.1.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.4">FortiADC 6.1.4</FullProductName>
                </Branch>
                <Branch Name="6.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.3">FortiADC 6.1.3</FullProductName>
                </Branch>
                <Branch Name="6.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.2">FortiADC 6.1.2</FullProductName>
                </Branch>
                <Branch Name="6.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.1">FortiADC 6.1.1</FullProductName>
                </Branch>
                <Branch Name="6.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.0">FortiADC 6.1.0</FullProductName>
                </Branch>
                <Branch Name="6.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.4">FortiADC 6.0.4</FullProductName>
                </Branch>
                <Branch Name="6.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.3">FortiADC 6.0.3</FullProductName>
                </Branch>
                <Branch Name="6.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.2">FortiADC 6.0.2</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.1">FortiADC 6.0.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.0">FortiADC 6.0.0</FullProductName>
                </Branch>
                <Branch Name="5.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.5">FortiADC 5.4.5</FullProductName>
                </Branch>
                <Branch Name="5.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.4">FortiADC 5.4.4</FullProductName>
                </Branch>
                <Branch Name="5.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.3">FortiADC 5.4.3</FullProductName>
                </Branch>
                <Branch Name="5.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.2">FortiADC 5.4.2</FullProductName>
                </Branch>
                <Branch Name="5.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.1">FortiADC 5.4.1</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.0">FortiADC 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.3.7" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.7">FortiADC 5.3.7</FullProductName>
                </Branch>
                <Branch Name="5.3.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.6">FortiADC 5.3.6</FullProductName>
                </Branch>
                <Branch Name="5.3.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.5">FortiADC 5.3.5</FullProductName>
                </Branch>
                <Branch Name="5.3.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.4">FortiADC 5.3.4</FullProductName>
                </Branch>
                <Branch Name="5.3.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.3">FortiADC 5.3.3</FullProductName>
                </Branch>
                <Branch Name="5.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.2">FortiADC 5.3.2</FullProductName>
                </Branch>
                <Branch Name="5.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.1">FortiADC 5.3.1</FullProductName>
                </Branch>
                <Branch Name="5.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.0">FortiADC 5.3.0</FullProductName>
                </Branch>
                <Branch Name="5.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.8">FortiADC 5.2.8</FullProductName>
                </Branch>
                <Branch Name="5.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.7">FortiADC 5.2.7</FullProductName>
                </Branch>
                <Branch Name="5.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.6">FortiADC 5.2.6</FullProductName>
                </Branch>
                <Branch Name="5.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.5">FortiADC 5.2.5</FullProductName>
                </Branch>
                <Branch Name="5.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.4">FortiADC 5.2.4</FullProductName>
                </Branch>
                <Branch Name="5.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.3">FortiADC 5.2.3</FullProductName>
                </Branch>
                <Branch Name="5.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.2">FortiADC 5.2.2</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.1">FortiADC 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.0">FortiADC 5.2.0</FullProductName>
                </Branch>
                <Branch Name="5.1.7" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.7">FortiADC 5.1.7</FullProductName>
                </Branch>
                <Branch Name="5.1.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.6">FortiADC 5.1.6</FullProductName>
                </Branch>
                <Branch Name="5.1.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.5">FortiADC 5.1.5</FullProductName>
                </Branch>
                <Branch Name="5.1.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.4">FortiADC 5.1.4</FullProductName>
                </Branch>
                <Branch Name="5.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.3">FortiADC 5.1.3</FullProductName>
                </Branch>
                <Branch Name="5.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.2">FortiADC 5.1.2</FullProductName>
                </Branch>
                <Branch Name="5.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.1">FortiADC 5.1.1</FullProductName>
                </Branch>
                <Branch Name="5.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.1.0">FortiADC 5.1.0</FullProductName>
                </Branch>
                <Branch Name="5.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.0.4">FortiADC 5.0.4</FullProductName>
                </Branch>
                <Branch Name="5.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.0.3">FortiADC 5.0.3</FullProductName>
                </Branch>
                <Branch Name="5.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.0.2">FortiADC 5.0.2</FullProductName>
                </Branch>
                <Branch Name="5.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.0.1">FortiADC 5.0.1</FullProductName>
                </Branch>
                <Branch Name="5.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.0.0">FortiADC 5.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Unverified password change over the GUI</Title>
        <cvrf:CVE>CVE-2022-27484</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiADC-6.2.3</ProductID>
                <ProductID>FortiADC-6.2.2</ProductID>
                <ProductID>FortiADC-6.2.1</ProductID>
                <ProductID>FortiADC-6.2.0</ProductID>
                <ProductID>FortiADC-6.1.6</ProductID>
                <ProductID>FortiADC-6.1.5</ProductID>
                <ProductID>FortiADC-6.1.4</ProductID>
                <ProductID>FortiADC-6.1.3</ProductID>
                <ProductID>FortiADC-6.1.2</ProductID>
                <ProductID>FortiADC-6.1.1</ProductID>
                <ProductID>FortiADC-6.1.0</ProductID>
                <ProductID>FortiADC-6.0.4</ProductID>
                <ProductID>FortiADC-6.0.3</ProductID>
                <ProductID>FortiADC-6.0.2</ProductID>
                <ProductID>FortiADC-6.0.1</ProductID>
                <ProductID>FortiADC-6.0.0</ProductID>
                <ProductID>FortiADC-5.4.5</ProductID>
                <ProductID>FortiADC-5.4.4</ProductID>
                <ProductID>FortiADC-5.4.3</ProductID>
                <ProductID>FortiADC-5.4.2</ProductID>
                <ProductID>FortiADC-5.4.1</ProductID>
                <ProductID>FortiADC-5.4.0</ProductID>
                <ProductID>FortiADC-5.3.7</ProductID>
                <ProductID>FortiADC-5.3.6</ProductID>
                <ProductID>FortiADC-5.3.5</ProductID>
                <ProductID>FortiADC-5.3.4</ProductID>
                <ProductID>FortiADC-5.3.3</ProductID>
                <ProductID>FortiADC-5.3.2</ProductID>
                <ProductID>FortiADC-5.3.1</ProductID>
                <ProductID>FortiADC-5.3.0</ProductID>
                <ProductID>FortiADC-5.2.8</ProductID>
                <ProductID>FortiADC-5.2.7</ProductID>
                <ProductID>FortiADC-5.2.6</ProductID>
                <ProductID>FortiADC-5.2.5</ProductID>
                <ProductID>FortiADC-5.2.4</ProductID>
                <ProductID>FortiADC-5.2.3</ProductID>
                <ProductID>FortiADC-5.2.2</ProductID>
                <ProductID>FortiADC-5.2.1</ProductID>
                <ProductID>FortiADC-5.2.0</ProductID>
                <ProductID>FortiADC-5.1.7</ProductID>
                <ProductID>FortiADC-5.1.6</ProductID>
                <ProductID>FortiADC-5.1.5</ProductID>
                <ProductID>FortiADC-5.1.4</ProductID>
                <ProductID>FortiADC-5.1.3</ProductID>
                <ProductID>FortiADC-5.1.2</ProductID>
                <ProductID>FortiADC-5.1.1</ProductID>
                <ProductID>FortiADC-5.1.0</ProductID>
                <ProductID>FortiADC-5.0.4</ProductID>
                <ProductID>FortiADC-5.0.3</ProductID>
                <ProductID>FortiADC-5.0.2</ProductID>
                <ProductID>FortiADC-5.0.1</ProductID>
                <ProductID>FortiADC-5.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>5.1</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-055</URL>
                <Description>Unverified password change over the GUI</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>