cbcvebase.
CVE-2024-52966
published 2025-02-11

CVE-2024-52966: An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via…

PriorityP45low2.3CVSS 3.1
AVLACLPRHUINSUCLINAN
EPSS
0.21%
10.8th percentile
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer>= 6.4.0 < 7.2.87.2.8
fortinetfortianalyzer6.4.0 – 6.4.15
fortinetfortianalyzer7.0.0 – 7.0.13
fortinetfortianalyzer7.2.0 – 7.2.7
fortinetfortianalyzer>= 7.4.0 < 7.4.57.4.5
fortinetfortianalyzer7.4.0 – 7.4.4
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.