A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.2.6Upgrade FortiAnalyzer to 7.0.10Upgrade FortiAnalyzer to 7.4.1Upgrade FortiAnalyzer to 7.2.4Upgrade to the latest version of FortiAnalyzer | Oct 16, 2023 | Oct 10, 2023 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.0.10Upgrade to the latest version of FortiManagerUpgrade FortiManager to 7.4.1Upgrade FortiManager to 7.2.4 | May 25, 2026 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub