A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData
at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-396 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Jan 2025, 22:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet fortimanager
Fortinet Fortinet fortianalyzer Fortinet fortianalyzer Big Data |
|
CWE | NVD-CWE-Other | |
CPE | cpe:2.3:a:fortinet:fortianalyzer_big_data:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer_big_data:7.4.0:*:*:*:*:*:*:* |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-396 - Vendor Advisory |
Information
Published : 2024-11-12 19:15
Updated : 2025-01-21 22:04
NVD link : CVE-2024-23666
Mitre link : CVE-2024-23666
CVE.ORG link : CVE-2024-23666
JSON object : View
Products Affected
fortinet
- fortianalyzer
- fortimanager
- fortianalyzer_big_data
CWE