Filtered by vendor Fortinet Subscriptions
Filtered by product Fortianalyzer-bigdata Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-44254 1 Fortinet 3 Fortianalyzer, Fortianalyzer-bigdata, Fortimanager 2024-09-25 4.7 Medium
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
CVE-2023-42782 1 Fortinet 3 Fortianalyzer, Fortianalyzer-bigdata, Fortimanager 2024-09-18 5 Medium
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.