CVE-2023-44249
published 2023-10-10CVE-2023-44249: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.87%
54.9th percentile
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.2.0 – 6.2.12 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.13 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.9 | — |
| fortinet | fortianalyzer | >= 7.2.0 < 7.2.4 | 7.2.4 |
| fortinet | fortianalyzer | 7.2.0 – 7.2.3 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 6.2.0 – 6.2.12 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.13 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.9 | — |
| fortinet | fortimanager | >= 7.2.0 < 7.2.4 | 7.2.4 |
| fortinet | fortimanager | 7.2.0 – 7.2.3 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7m9-r72h-m8v2: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7
ghsa_unreviewed·2023-10-10
CVE-2023-44249 [MEDIUM] CWE-639 GHSA-c7m9-r72h-m8v2: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
Fortinet
Authorization bypass via key value controlled by user
vendor_fortinet·2023-10-10·CVSS 4.3
CVE-2023-44249 [MEDIUM] CWE-639 Authorization bypass via key value controlled by user
FG-IR-23-201: Authorization bypass via key value controlled by user
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
CVEs: CVE-2023-44249
CWEs: CWE-639
CVSS: 4.3 (medium)
Affected products: FortiAnalyzer, FortiManager, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-10
Published