Description
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiManager version 7.4.1 or above Please upgrade to FortiManager version 7.2.4 or above Please upgrade to FortiAnalyzer version 7.4.1 or above Please upgrade to FortiAnalyzer version 7.2.4 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48608 | An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests. |
References
History
No history.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-02-13T17:13:33.898Z
Reserved: 2023-09-27T12:26:48.750Z
Link: CVE-2023-44249
No data.
Status : Modified
Published: 2023-10-10T17:15:13.047
Modified: 2024-11-21T08:25:31.080
Link: CVE-2023-44249
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD