CVE-2023-44249
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 10, 2023
Updated: Dec 21, 2023
CWE ID 639
Summary
CVE-2023-44249 is a newly disclosed vulnerability affecting Fortinet FortiManager versions 7.4.0 and below, as well as FortiAnalyzer versions 7.4.0 and below. This issue involves an authorization bypass (CWE-639) that can be exploited by an attacker with low privileges. By sending crafted HTTP requests, the attacker is able to access sensitive information, bypassing the intended access controls. This vulnerability poses a significant risk and requires immediate attention from Fortinet users to apply the available patch to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiManager
- FortiAnalyzer
Affected Vendors
- Fortinet