PT-2024-1745 · Fortinet · Fortianalyzer+2
François-Xavier Picard
+3
·
Published
2024-02-08
·
Updated
2024-03-11
·
CVE-2023-44253
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiManager versions 7.4.0 through 7.4.1 and before 7.2.5
Fortinet FortiAnalyzer versions 7.4.0 through 7.4.1 and before 7.2.5
Fortinet FortiAnalyzer-BigData before 7.2.5
Description
The issue is related to the exposure of sensitive information to unauthorized actors. It allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests. This can be exploited by a remote attacker to disclose protected information.
Recommendations
For Fortinet FortiManager versions 7.4.0 through 7.4.1 and before 7.2.5, update to a version that includes the fix for this issue.
For Fortinet FortiAnalyzer versions 7.4.0 through 7.4.1 and before 7.2.5, update to a version that includes the fix for this issue.
For Fortinet FortiAnalyzer-BigData before 7.2.5, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to crafted HTTP or HTTPS requests to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortianalyzer
Fortianalyzer-Bigdata
Fortimanager