A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to version 6.4.6Upgrade FortiAnalyzer to version 6.2.8Upgrade FortiAnalyzer to version 7.0.1 | Aug 16, 2021 | Aug 5, 2021 |
| Fortinet Fortimanager | — | Upgrade FortiManager to version 6.2.8Upgrade FortiManager to version 6.4.6Upgrade FortiManager to version 6.4.5Upgrade FortiManager to version 6.0.11Upgrade FortiManager to version 7.0.1Upgrade FortiManager to version 6.2.7Upgrade FortiManager to version 5.6.9 | Aug 17, 2021 | Aug 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub