An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortimanager | 7.4.0 | 7.4.0.x |
| fortinet / fortimanager | 6.4.12 | 6.4.12.x |
| fortinet / fortimanager | 7.2.3 | 7.2.3.x |
| fortinet / fortimanager | 7.0.7 | 7.0.9 |