PT-2024-1745 · Fortinet · Fortianalyzer+2

François-Xavier Picard

+3

·

Published

2024-02-08

·

Updated

2024-03-11

·

CVE-2023-44253

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiManager versions 7.4.0 through 7.4.1 and before 7.2.5 Fortinet FortiAnalyzer versions 7.4.0 through 7.4.1 and before 7.2.5 Fortinet FortiAnalyzer-BigData before 7.2.5
Description The issue is related to the exposure of sensitive information to unauthorized actors. It allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests. This can be exploited by a remote attacker to disclose protected information.
Recommendations For Fortinet FortiManager versions 7.4.0 through 7.4.1 and before 7.2.5, update to a version that includes the fix for this issue. For Fortinet FortiAnalyzer versions 7.4.0 through 7.4.1 and before 7.2.5, update to a version that includes the fix for this issue. For Fortinet FortiAnalyzer-BigData before 7.2.5, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to crafted HTTP or HTTPS requests to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-01456
CVE-2023-44253
GHSA-25J8-69H7-83H2

Affected Products

Fortianalyzer
Fortianalyzer-Bigdata
Fortimanager