---
cve: "CVE-2024-23665"
severity: "MEDIUM"
cvss: 5.6
epss: "49%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2024-06-03 10:15:12"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T22:38:03+02:00"
---

# CVE-2024-23665

> 5.6 MEDIUM

## Beschreibung

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N/E:P/RL:X/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-285** — Improper Authorization
  The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

## Angriffsmuster (CAPEC)

- [CAPEC-1 — Accessing Functionality Not Properly Constrained by ACLs](https://capec.mitre.org/data/definitions/1.html) _(Severity: High)_
- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-17 — Using Malicious Files](https://capec.mitre.org/data/definitions/17.html) _(Severity: Very High)_
- [CAPEC-39 — Manipulating Opaque Client-based Data Tokens](https://capec.mitre.org/data/definitions/39.html) _(Severity: Medium)_
- [CAPEC-45 — Buffer Overflow via Symbolic Links](https://capec.mitre.org/data/definitions/45.html) _(Severity: High)_
- [CAPEC-104 — Cross Zone Scripting](https://capec.mitre.org/data/definitions/104.html) _(Severity: High)_
- [CAPEC-127 — Directory Indexing](https://capec.mitre.org/data/definitions/127.html) _(Severity: Medium)_
- [CAPEC-402 — Bypassing ATA Password Security](https://capec.mitre.org/data/definitions/402.html)

## ATT&CK-Techniken

- [T1574.010 — Hijack Execution Flow: ServicesFile Permissions Weakness](https://attack.mitre.org/techniques/T1574/010/)
- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)
- [T1574.005 — Hijack Execution Flow: Executable Installer File Permissions](https://attack.mitre.org/techniques/T1574/005/)
- [T1083 — File and Directory Discovery](https://attack.mitre.org/techniques/T1083/)

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-23-474>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-23665) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
