6.5
CVSSv3

CVE-2023-44249

Published: 10/10/2023 Updated: 21/12/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and prior to 7.2.3 and FortiAnalyzer version 7.4.0 and prior to 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortianalyzer

fortinet fortimanager

fortinet fortianalyzer 7.4.0

fortinet fortimanager 7.4.0