A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials.
CVSS Details
- CVSS 3.1 Base Score: 4.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.4.1Upgrade FortiAnalyzer to 7.2.4Upgrade FortiAnalyzer to 7.0.9 | Nov 22, 2023 | Nov 14, 2023 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.2.4Upgrade FortiManager to 7.4.1Upgrade FortiManager to 7.0.9 | Nov 23, 2023 | Nov 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub