Server-Side Request Forgery Vulnerability in Fortinet FortiAnalyzer and FortiManager
CVE-2023-44256
6.4MEDIUM
Summary
A server-side request forgery vulnerability found in Fortinet's FortiAnalyzer and FortiManager products allows remote attackers with low privileges to exploit internal systems. By crafting specific HTTP requests, these attackers can gain unauthorized access to sensitive data residing within the internal servers or conduct a local port scan. This vulnerability has implications for information confidentiality and organizational security, necessitating immediate attention and remediation.
Affected Version(s)
FortiAnalyzer 7.4.0
FortiAnalyzer 7.2.0 <= 7.2.3
FortiAnalyzer 7.0.2 <= 7.0.8
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved