Server-Side Request Forgery Vulnerability in Fortinet FortiAnalyzer and FortiManager
CVE-2023-44256

6.4MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
20 October 2023

Summary

A server-side request forgery vulnerability found in Fortinet's FortiAnalyzer and FortiManager products allows remote attackers with low privileges to exploit internal systems. By crafting specific HTTP requests, these attackers can gain unauthorized access to sensitive data residing within the internal servers or conduct a local port scan. This vulnerability has implications for information confidentiality and organizational security, necessitating immediate attention and remediation.

Affected Version(s)

FortiAnalyzer 7.4.0

FortiAnalyzer 7.2.0 <= 7.2.3

FortiAnalyzer 7.0.2 <= 7.0.8

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.