← Back

CVE-2023-44253

nvd nist
Published: Feb 15, 2024Modified: Nov 21, 2024

JSON object

Loading...
5.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 3.1 / Impact: 1.4
Source: NVD

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.

Affected (12)

2 products
Fortianalyzer
Fortimanager
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.2.0 to 6.2.12
From 6.4.0 to 6.4.14
From 7.0.0 to 7.0.11
From 7.2.0 to 7.2.3
Version 7.4.0
Version 7.4.1
Fortinet
From 6.2.0 to 6.2.12
From 6.4.0 to 6.4.14
From 7.0.0 to 7.0.11
From 7.2.0 to 7.2.3
Version 7.4.0
Version 7.4.1

References (4)

Timeline

No history available yet.