CVE-2023-44256

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
20/10/2023
Last modified:
07/11/2023

Description

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 6.4.8 (including) 6.4.13 (including)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.0.2 (including) 7.0.8 (including)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.3 (including)
cpe:2.3:a:fortinet:fortianalyzer:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.8 (including)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.3 (including)
cpe:2.3:a:fortinet:fortimanager:7.4.0:*:*:*:*:*:*:*