A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade to the latest version of FortiAnalyzerUpgrade FortiAnalyzer to 7.2.4Upgrade FortiAnalyzer to 7.0.10Upgrade FortiAnalyzer to 7.4.1 | Oct 16, 2023 | Oct 10, 2023 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.4.1Upgrade FortiManager to 7.2.4Upgrade to the latest version of FortiManagerUpgrade FortiManager to 7.0.10 | Oct 16, 2023 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub