CVE-2023-44255

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 359

Summary

CVE-2023-44255 is a cybersecurity vulnerability affecting Fortinet FortiManager versions before 7.4.2, FortiAnalyzer versions before 7.4.2, and FortiAnalyzer-BigData versions before 7.2.5. This issue (CWE-200) enables a privileged attacker with administrative read permissions to gain unauthorized access to the event logs of another administrative domain (adom) by crafting specific HTTP or HTTPs requests. This exposure of sensitive information poses a significant risk to organizational security. Unauthorized access to event logs can be used to gain insights into an organization's network activities, potentially leading to further attacks or breaches. It is crucial to apply the necessary patches to mitigate this vulnerability promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • FortiAnalyzer
  • FortiManager

Affected Vendors

  • Fortinet