cbcvebase.
CVE-2023-42787
published 2023-10-10

CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version…

PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.37%
68.9th percentile
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.

Affected

13 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer6.2.0 – 6.2.12
fortinetfortianalyzer6.4.0 – 6.4.13
fortinetfortianalyzer7.0.0 – 7.0.9
fortinetfortianalyzer7.2.0 – 7.2.3
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager6.2.0 – 6.2.12
fortinetfortimanager6.4.0 – 6.4.13
fortinetfortimanager7.0.0 – 7.0.9
fortinetfortimanager7.2.0 – 7.2.3
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.