PT-2023-5994 · Fortinet · Fortianalyzer+1

François-Xavier Picard

+3

·

Publicado

2023-10-10

·

Atualizado

2023-12-21

·

CVE-2023-42787

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiManager versions 7.4.0 and before 7.2.3 Fortinet FortiAnalyzer versions 7.4.0 and before 7.2.3
Description The issue is related to the implementation of client-side security features. It may allow a remote attacker with low privileges to access a privileged web console via client-side code execution. This is due to a client-side enforcement of server-side security vulnerability.
Recommendations For Fortinet FortiManager versions 7.4.0 and before 7.2.3, update to a version after 7.2.3 to resolve the issue. For Fortinet FortiAnalyzer versions 7.4.0 and before 7.2.3, update to a version after 7.2.3 to resolve the issue. As a temporary workaround, consider restricting access to the web console to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06695
CVE-2023-42787
GHSA-Q5PQ-8666-J8FR

Produtos afetados

Fortianalyzer
Fortimanager