PT-2023-5994 · Fortinet · Fortianalyzer+1

François-Xavier Picard

+3

·

Published

2023-10-10

·

Updated

2023-12-21

·

CVE-2023-42787

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiManager versions 7.4.0 and before 7.2.3 Fortinet FortiAnalyzer versions 7.4.0 and before 7.2.3
Description The issue is related to the implementation of client-side security features. It may allow a remote attacker with low privileges to access a privileged web console via client-side code execution. This is due to a client-side enforcement of server-side security vulnerability.
Recommendations For Fortinet FortiManager versions 7.4.0 and before 7.2.3, update to a version after 7.2.3 to resolve the issue. For Fortinet FortiAnalyzer versions 7.4.0 and before 7.2.3, update to a version after 7.2.3 to resolve the issue. As a temporary workaround, consider restricting access to the web console to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-06695
CVE-2023-42787
GHSA-Q5PQ-8666-J8FR

Affected Products

Fortianalyzer
Fortimanager