cbcvebase.
CVE-2023-44249
published 2023-10-10

CVE-2023-44249: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.87%
54.9th percentile
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.

Affected

15 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer6.2.0 – 6.2.12
fortinetfortianalyzer6.4.0 – 6.4.13
fortinetfortianalyzer7.0.0 – 7.0.9
fortinetfortianalyzer>= 7.2.0 < 7.2.47.2.4
fortinetfortianalyzer7.2.0 – 7.2.3
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager6.2.0 – 6.2.12
fortinetfortimanager6.4.0 – 6.4.13
fortinetfortimanager7.0.0 – 7.0.9
fortinetfortimanager>= 7.2.0 < 7.2.47.2.4
fortinetfortimanager7.2.0 – 7.2.3
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.