CVE-2023-42787Client-Side Enforcement of Server-Side Security in Fortinet Fortianalyzer

Severity
6.5MEDIUMNVD
EPSS
0.8%
top 26.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10

Description

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5fortinet/fortimanager7.2.07.2.3+4
NVDfortinet/fortimanager6.2.06.2.12+4
CVEListV5fortinet/fortianalyzer7.2.07.2.3+4
NVDfortinet/fortianalyzer6.2.06.2.12+4

🔴Vulnerability Details

2
GHSA
GHSA-p47r-gpqq-3w72: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 72023-10-10
CVEList
CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 72023-10-10

📋Vendor Advisories

1
Fortinet
Unprivileged user can access web console and run some unauthorized commands2023-10-10
CVE-2023-42787 — Fortinet Fortianalyzer vulnerability | cvebase