CVE-2023-44255

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2024
Last modified:
21/01/2025

Description

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 6.2.0 (including) 7.4.3 (excluding)
cpe:2.3:a:fortinet:fortianalyzer_big_data:*:*:*:*:*:*:*:* 6.2.1 (including) 7.2.6 (excluding)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 6.2.0 (including) 7.4.3 (excluding)


References to Advisories, Solutions, and Tools