cbcvebase.
CVE-2024-23666
published 2024-11-12

CVE-2024-23666: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.74%
84.5th percentile
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.

Affected

22 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 6.4.0 < 6.4.156.4.15
fortinetfortianalyzer6.4.0 – 6.4.14
fortinetfortianalyzer>= 7.0.0 < 7.0.137.0.13
fortinetfortianalyzer7.0.0 – 7.0.11
fortinetfortianalyzer>= 7.2.0 < 7.2.67.2.6
fortinetfortianalyzer7.2.0 – 7.2.4
fortinetfortianalyzer>= 7.4.0 < 7.4.37.4.3
fortinetfortianalyzer7.4.0 – 7.4.1
fortinetfortianalyzer_big_data
fortinetfortianalyzer_big_data>= 6.2.1 < 7.2.77.2.7
fortinetfortianalyzerbigdata
fortinetfortimanager
fortinetfortimanager>= 6.4.0 < 6.4.156.4.15
fortinetfortimanager6.4.0 – 6.4.14
fortinetfortimanager>= 7.0.0 < 7.0.137.0.13
fortinetfortimanager7.0.0 – 7.0.11
fortinetfortimanager>= 7.2.0 < 7.2.67.2.6
fortinetfortimanager7.2.0 – 7.2.4
fortinetfortimanager>= 7.4.0 < 7.4.37.4.3
fortinetfortimanager7.4.0 – 7.4.1
fortinetfortinet

Detection & IOCsextracted from sources · hover to see the quote

  • Readonly users crafting direct API/backend requests to bypass client-side enforcement and perform sensitive operations — monitor for privilege-mismatched API calls from accounts with readonly roles on FortiAnalyzer, FortiAnalyzer-BigData, and FortiManager
  • Detect crafted requests that circumvent client-side access controls to reach server-side sensitive operations — look for unexpected write/execute-class API calls originating from readonly-privileged sessions
  • ·Vulnerability is a client-side enforcement of server-side security (CWE-602); the server does not re-validate permissions, meaning access control is only enforced in the UI/client layer — any direct API call bypasses it entirely
  • ·Affected scope is broad across three product lines and many versions: FortiAnalyzer 6.4.0–6.4.14, 7.0.0–7.0.11, 7.2.0–7.2.4, 7.4.0–7.4.1; FortiManager 6.4.0–6.4.14, 7.0.0–7.0.11, 7.2.0–7.2.4, 7.4.0–7.4.1; FortiAnalyzer-BigData 6.2.5, 6.4.5–6.4.7, 7.0.1–7.0.6, 7.2.0–7.2.6, 7.4.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.