CVE-2023-42787
published 2023-10-10CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.37%
68.9th percentile
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.2.0 – 6.2.12 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.13 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.9 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.3 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 6.2.0 – 6.2.12 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.13 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.9 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.3 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p47r-gpqq-3w72: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7
ghsa_unreviewed·2023-10-10
CVE-2023-42787 [MEDIUM] CWE-602 GHSA-p47r-gpqq-3w72: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
Fortinet
Unprivileged user can access web console and run some unauthorized commands
vendor_fortinet·2023-10-10·CVSS 6.5
CVE-2023-42787 [MEDIUM] CWE-602 Unprivileged user can access web console and run some unauthorized commands
FG-IR-23-187: Unprivileged user can access web console and run some unauthorized commands
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
CVEs: CVE-2023-42787
CWEs: CWE-602
CVSS: 6.5 (medium)
Affected products: FortiAnalyzer, FortiManager, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-10
Published