Improper Output Neutralization Vulnerability in Fortinet FortiAnalyzer and FortiManager
CVE-2024-52962
5MEDIUM
Summary
An improper output neutralization vulnerability in Fortinet's FortiAnalyzer and FortiManager products allows unauthenticated remote attackers to manipulate log files. By sending specially crafted login requests, they can introduce malicious content into the logs, potentially leading to further exploitation. This issue affects multiple versions of both products, underscoring the importance of updating to secure releases to mitigate risks associated with log pollution and its implications in security monitoring.
Affected Version(s)
FortiAnalyzer 7.6.0 <= 7.6.1
FortiAnalyzer 7.4.0 <= 7.4.5
FortiAnalyzer 7.2.0 <= 7.2.8
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved