Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:H/RL:O/RC:CDefault status
unaffected
7.6.0 (semver)
affected
7.5.0 (semver)
affected
7.4.0 (semver)
affected
7.3.0 (semver)
affected
Default status
unaffected
7.6.0 (semver)
affected
7.5.0 (semver)
affected
7.4.0 (semver)
affected
7.3.0 (semver)
affected
Description
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password
Problem types
Product status
7.6.0 (semver)
7.5.0 (semver)
7.4.0 (semver)
7.3.0 (semver)
7.6.0 (semver)
7.5.0 (semver)
7.4.0 (semver)
7.3.0 (semver)
References
fortiguard.fortinet.com/psirt/FG-IR-25-599