CVE-2024-23666
published 2024-11-12CVE-2024-23666: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.74%
84.5th percentile
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData
at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.4.0 < 6.4.15 | 6.4.15 |
| fortinet | fortianalyzer | 6.4.0 – 6.4.14 | — |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.13 | 7.0.13 |
| fortinet | fortianalyzer | 7.0.0 – 7.0.11 | — |
| fortinet | fortianalyzer | >= 7.2.0 < 7.2.6 | 7.2.6 |
| fortinet | fortianalyzer | 7.2.0 – 7.2.4 | — |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortianalyzer | 7.4.0 – 7.4.1 | — |
| fortinet | fortianalyzer_big_data | — | — |
| fortinet | fortianalyzer_big_data | >= 6.2.1 < 7.2.7 | 7.2.7 |
| fortinet | fortianalyzerbigdata | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 6.4.15 | 6.4.15 |
| fortinet | fortimanager | 6.4.0 – 6.4.14 | — |
| fortinet | fortimanager | >= 7.0.0 < 7.0.13 | 7.0.13 |
| fortinet | fortimanager | 7.0.0 – 7.0.11 | — |
| fortinet | fortimanager | >= 7.2.0 < 7.2.6 | 7.2.6 |
| fortinet | fortimanager | 7.2.0 – 7.2.4 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 7.4.0 – 7.4.1 | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Readonly users crafting direct API/backend requests to bypass client-side enforcement and perform sensitive operations — monitor for privilege-mismatched API calls from accounts with readonly roles on FortiAnalyzer, FortiAnalyzer-BigData, and FortiManager ↗
- →Detect crafted requests that circumvent client-side access controls to reach server-side sensitive operations — look for unexpected write/execute-class API calls originating from readonly-privileged sessions ↗
- ·Vulnerability is a client-side enforcement of server-side security (CWE-602); the server does not re-validate permissions, meaning access control is only enforced in the UI/client layer — any direct API call bypasses it entirely ↗
- ·Affected scope is broad across three product lines and many versions: FortiAnalyzer 6.4.0–6.4.14, 7.0.0–7.0.11, 7.2.0–7.2.4, 7.4.0–7.4.1; FortiManager 6.4.0–6.4.14, 7.0.0–7.0.11, 7.2.0–7.2.4, 7.4.0–7.4.1; FortiAnalyzer-BigData 6.2.5, 6.4.5–6.4.7, 7.0.1–7.0.6, 7.2.0–7.2.6, 7.4.0 ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwm4-jq46-9g26: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData
at least version 7
ghsa_unreviewed·2024-11-12
CVE-2024-23666 [HIGH] CWE-602 GHSA-jwm4-jq46-9g26: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData
at least version 7
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData
at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
Fortinet
Readonly users could run some sensitive operations
vendor_fortinet·2024-11-12·CVSS 7.5
CVE-2024-23666 [HIGH] CWE-602 Readonly users could run some sensitive operations
FG-IR-23-396: Readonly users could run some sensitive operations
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData
at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
CVEs: CVE-2024-23666
CWEs: CWE-602
CVSS: 7.5 (high)
Affected products: FortiAnalyzer, FortiAnalyzerbigdata, FortiManager, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published