cbcvebase.
CVE-2023-44254
published 2024-09-10

CVE-2023-44254: An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.

Affected

16 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer>= 6.2.0 < 7.2.57.2.5
fortinetfortianalyzer6.2.0 – 6.2.12
fortinetfortianalyzer6.4.0 – 6.4.14
fortinetfortianalyzer7.0.0 – 7.0.12
fortinetfortianalyzer7.2.0 – 7.2.4
fortinetfortianalyzer_big_data7.2.0 – 7.2.5
fortinetfortianalyzerbigdata
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager>= 6.2.0 < 7.2.57.2.5
fortinetfortimanager6.2.0 – 6.2.12
fortinetfortimanager6.4.0 – 6.4.14
fortinetfortimanager7.0.0 – 7.0.12
fortinetfortimanager7.2.0 – 7.2.4