An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-48608 | An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests. |
Fixes
Solution
Please upgrade to FortiManager version 7.4.1 or above Please upgrade to FortiManager version 7.2.4 or above Please upgrade to FortiAnalyzer version 7.4.1 or above Please upgrade to FortiAnalyzer version 7.2.4 or above
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-02-13T17:13:33.898Z
Reserved: 2023-09-27T12:26:48.750Z
Link: CVE-2023-44249

No data.

Status : Modified
Published: 2023-10-10T17:15:13.047
Modified: 2024-11-21T08:25:31.080
Link: CVE-2023-44249

No data.

No data.