cbcvebase.
CVE-2023-44256
published 2023-10-20

CVE-2023-44256: A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager…

PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.22%
65.4th percentile
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer6.4.8 – 6.4.13
fortinetfortianalyzer7.0.2 – 7.0.8
fortinetfortianalyzer7.2.0 – 7.2.3
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager7.0.0 – 7.0.8
fortinetfortimanager7.2.0 – 7.2.3
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.