VYPR
Medium severity4.2NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026

CVE-2022-38378

CVE-2022-38378

Description

An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.

Affected products

6
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.1.0,<=2.0.9
    • (no CPE)range: 7.2.0 through 7.2.1 and <7.0.7
    • (no CPE)range: 7.2.0
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.0.0,<7.0.8
    • (no CPE)range: <=7.2.0 and <7.0.7
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.