CVE-2023-42782
published 2023-10-10CVE-2023-42782: A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.31%
23.4th percentile
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.2.0 – 6.2.12 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.13 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.9 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Syslog not protected by an extra layer of authentication
vendor_fortinet·2023-10-10·CVSS 5.3
CVE-2023-42782 [MEDIUM] CWE-345 Syslog not protected by an extra layer of authentication
FG-IR-23-221: Syslog not protected by an extra layer of authentication
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
CVEs: CVE-2023-42782
CWEs: CWE-345
CVSS: 5.3 (medium)
Affected products: FortiAnalyzer
GHSA
GHSA-g4h5-9rrr-q667: A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7
ghsa_unreviewed·2023-10-10
CVE-2023-42782 [MEDIUM] CWE-345 GHSA-g4h5-9rrr-q667: A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-10
Published