CVE-2024-52962
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager
Description
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.
Weakness: CWE-117
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAnalyzer | SIEM & Log Management | cna-assigner |
| Fortinet | FortiManager | Network & Security Management | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiAnalyzer
- Fortinet · FortiManager
Credit
Fortinet is pleased to thank Alexandre Labb from A1 Digital International for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiAnalyzer version 7.6.2 or above Please upgrade to FortiAnalyzer version 7.4.6 or above Please upgrade to FortiAnalyzer version 7.2.9 or above Please upgrade to FortiAnalyzer version 7.0.14 or above Please upgrade to FortiManager version 7.6.2 or above Please upgrade to FortiManager version 7.4.6 or above Please upgrade to FortiManager version 7.2.9 or above Please upgrade to FortiManager version 7.0.14 or above