Medium severity4.3NVD Advisory· Published Sep 10, 2024· Updated Jun 17, 2026
CVE-2024-45323
CVE-2024-45323
Description
An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:fortinet:fortiedrmanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiedrmanager:*:*:*:*:*:*:*:*range: >=6.2.0,<6.2.2
- cpe:2.3:a:fortinet:fortiedrmanager:6.0.1:*:*:*:*:*:*:*
- Range: 6.2.0 through 6.2.2, 6.0
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-24-371nvdVendor Advisory
News mentions
0No linked articles in our index yet.