Home
MEDIUM: 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:CDefault status
unaffected
7.6.0 (semver)
affected
7.4.0 (semver)
affected
7.2.2 (semver)
affected
Default status
unaffected
7.6.0 (semver)
affected
7.4.0 (semver)
affected
7.2.2 (semver)
affected
Description
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Problem types
Product status
7.6.0 (semver)
7.4.0 (semver)
7.2.2 (semver)
7.6.0 (semver)
7.4.0 (semver)
7.2.2 (semver)
References
fortiguard.fortinet.com/psirt/FG-IR-26-090