CVE-2024-23666

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiMan

Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.027
85.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Nov 12, 2024
Assigned by fortinet

Description

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.

Weakness: CWE-602

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiManager
  • Fortinet · FortiAnalyzer

Credit

Fortinet is pleased to thank security researchers Paul BARBE, Antoine CARRINCAZEAUX and Clément AMIC from Synacktiv ( https://www.synacktiv.com) for discovering and reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiAnalyzer-BigData version 7.4.1 or above Please upgrade to FortiAnalyzer-BigData version 7.2.7 or above Please upgrade to FortiManager version 7.4.3 or above Please upgrade to FortiManager version 7.2.6 or above Please upgrade to FortiManager version 7.0.13 or above Please upgrade to FortiManager version 6.4.15 or above Please upgrade to FortiAnalyzer version 7.4.3 or above Please upgrade to FortiAnalyzer version 7.2.6 or above Please upgrade to FortiAnalyzer version 7.0.13 or above Please upgrade to FortiAnalyzer version 6.4.15 or above

Something wrong here?