CVE-2023-36554

CRITICAL

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execut...

Affects 1 product across 1 vendor.

BCS6.72
CVSS 3.19.8
EPSS0.8%
Percentile53th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "A critical vulnerability in Fortinet FortiManager versions 7.4.0, 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 6.4.0 through 6.4.13, and all versions of 6.2 allows unauthorized code or command execution via specially crafted HTTP requests due to improper access control.", "attack_vector_detail": "The vulnerability is exploited by sending specially crafted HTTP requests to the affected FortiManager systems. This can lead to unauthorized access and execution of arbitrary code or commands, potentially compromising the entire network managed by the FortiManager.", "affected_components": ["FortiManager 7.4.0", "FortiManager 7.2.0-7.2.3", "FortiManager 7.0.0-7.0.10", "FortiManager 6.4.0-6.4.13", "FortiManager 6.2 all versions"], "exploitation_likelihood": "CRITICAL", "remediation_priority": "IMMEDIATE", "confidence

BSID: BS-2024-GLOBAL-005070-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-36554?
{ "executive_summary": "A critical vulnerability in Fortinet FortiManager versions 7.4.0, 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 6.4.0 through 6.4.13, and all versions of 6.2 allows unauthorized code or command execution via specially crafted HTTP requests due to improper access control.", "attack_vector_detail": "The vulnerability is exploited by sending specially crafted HTTP requests to the affected FortiManager systems. This can lead to unauthorized access and execution of arbitrary
What is the CVSS score for CVE-2023-36554?
CVE-2023-36554 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.8%.
Is CVE-2023-36554 actively exploited?
No confirmed active exploitation of CVE-2023-36554 as of 2026-05-30.
How do I remediate CVE-2023-36554?
Priority: HIGH. Advisory: https://fortiguard.com/psirt/FG-IR-23-103 PSIRT: [email protected]
What systems are affected by CVE-2023-36554?
CVE-2023-36554 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2023-36554
BSIDBS-2024-GLOBAL-005070-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-03-12
Last Modified2024-11-21
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Fortinet Fortimanager
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 890 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash5908fa12f85b0991b776550975a43cb68d3bcf2450242349e52c30d59424722034dd2840069108b3670b7bbf38d40b1011870551d1754b8b2dab214612161dc1
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2018-13379 9.8 An Improper Limitation of a Pathname to a Restricted Directory ("Path Travers... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2025-25249 9.8 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through ... CVE-2023-47539 9.8 An improper access control vulnerability in FortiMail version 7.4.0 configure...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →