CVE-2023-44255
published 2024-11-12CVE-2023-44255: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and…
PriorityP418medium4.1CVSS 3.1
AVNACLPRHUINSCCLINAN
EPSS
0.54%
41.5th percentile
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.2.0 < 7.4.3 | 7.4.3 |
| fortinet | fortianalyzer | 6.2.0 – 6.2.13 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.15 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.13 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.3 | — |
| fortinet | fortianalyzer | 7.4.0 – 7.4.2 | — |
| fortinet | fortianalyzer_big_data | >= 6.2.1 < 7.2.6 | 7.2.6 |
| fortinet | fortianalyzerbigdata | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.2.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 6.2.0 – 6.2.13 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.13 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.5 | — |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Lack of capacity to filter logs by administrator access
vendor_fortinet·2024-11-12·CVSS 4.1
CVE-2023-44255 [MEDIUM] CWE-359 Lack of capacity to filter logs by administrator access
FG-IR-23-267: Lack of capacity to filter logs by administrator access
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
CVEs: CVE-2023-44255
CWEs: CWE-359
CVSS: 4.1 (medium)
Affected products: FortiAnalyzer, FortiAnalyzerbigdata, FortiManager, Fortinet
GHSA
GHSA-cmm4-x589-xjmx: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7
ghsa_unreviewed·2024-11-12
CVE-2023-44255 [MEDIUM] CWE-359 GHSA-cmm4-x589-xjmx: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published