CVE-2024-33506
published 2024-10-08CVE-2024-33506: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.44%
35.7th percentile
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 7.0.0 < 7.2.6 | 7.2.6 |
| fortinet | fortimanager | 7.0.0 – 7.0.12 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.5 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wrc2-47qv-9p22: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7
ghsa_unreviewed·2024-10-08
CVE-2024-33506 [LOW] CWE-200 GHSA-wrc2-47qv-9p22: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
Fortinet
Priviledged admin able to view device summary for device in different ADOM
vendor_fortinet·2024-10-08·CVSS 3.3
CVE-2024-33506 [LOW] CWE-200 Priviledged admin able to view device summary for device in different ADOM
FG-IR-23-472: Priviledged admin able to view device summary for device in different ADOM
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
CVEs: CVE-2024-33506
CWEs: CWE-200
CVSS: 3.3 (low)
Affected products: FortiManager
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-08
Published