CVE-2023-44255
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Summary
CVE-2023-44255 is a cybersecurity vulnerability affecting Fortinet FortiManager versions before 7.4.2, FortiAnalyzer versions before 7.4.2, and FortiAnalyzer-BigData versions before 7.2.5. This issue (CWE-200) enables a privileged attacker with administrative read permissions to gain unauthorized access to the event logs of another administrative domain (adom) by crafting specific HTTP or HTTPs requests. This exposure of sensitive information poses a significant risk to organizational security. Unauthorized access to event logs can be used to gain insights into an organization's network activities, potentially leading to further attacks or breaches. It is crucial to apply the necessary patches to mitigate this vulnerability promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiAnalyzer
- FortiManager
Affected Vendors
- Fortinet