CVE-2024-52966
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.
Severity
Low 2.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.6th percentile
Discovered by
Third party
Vendor advisory field
Published
Feb 11, 2025
Assigned by fortinet
Description
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAnalyzer | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiAnalyzer
Credit
External
Vendor remediation
Please upgrade to FortiAnalyzer version 7.6.1 or above Please upgrade to FortiAnalyzer version 7.4.5 or above Please upgrade to FortiAnalyzer version 7.2.8 or above Please upgrade to FortiManager version 7.6.1 or above Please upgrade to FortiManager version 7.4.5 or above Please upgrade to FortiManager version 7.2.8 or above