cbcvebase.
CVE-2023-44253
published 2024-02-15

CVE-2023-44253: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5…

PriorityP428medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.68%
48.2th percentile
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.

Affected

17 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer6.2.0 – 6.2.12
fortinetfortianalyzer6.4.0 – 6.4.14
fortinetfortianalyzer7.0.0 – 7.0.11
fortinetfortianalyzer7.2.0 – 7.2.3
fortinetfortianalyzer7.4.0 – 7.4.1
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager6.2.0 – 6.2.12
fortinetfortimanager6.4.0 – 6.4.14
fortinetfortimanager7.0.0 – 7.0.11
fortinetfortimanager7.2.0 – 7.2.3
fortinetfortimanager7.4.0 – 7.4.1
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.