A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Solution:
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Link | Tags |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-435 | vendor advisory |