CVE-2023-44255

CWE-3594 documents4 sources
Severity
4.1MEDIUM
EPSS
0.1%
top 65.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:NExploitability: 2.3 | Impact: 1.4

Affected Packages5 packages

NVDfortinet/fortianalyzer_big_data6.2.17.2.6
NVDfortinet/fortianalyzer6.2.07.4.3
CVEListV5fortinet/fortianalyzer7.4.07.4.2+4
NVDfortinet/fortimanager6.2.07.4.3
CVEListV5fortinet/fortimanager7.4.07.4.2+4

🔴Vulnerability Details

2
GHSA
GHSA-cmm4-x589-xjmx: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 72024-11-12
CVEList
CVE-2023-44255: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 72024-11-12

📋Vendor Advisories

1
Fortinet
Lack of capacity to filter logs by administrator access2024-11-12
CVE-2023-44255 (MEDIUM CVSS 4.1) | An exposure of sensitive informatio | cvebase.io