CVE-2023-25609: SSRF in FortiGuard Outbreak feature
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
Other sources
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-25609?
CVE-2023-25609 is a server-side request forgery (SSRF) vulnerability in FortiManager and FortiAnalyzer GUI versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, and 6.4.8 through 6.4.11.
What is the severity of CVE-2023-25609?
CVE-2023-25609 has a severity score of 6.5, which is considered medium.
How does CVE-2023-25609 impact FortiManager and FortiAnalyzer?
CVE-2023-25609 may allow a remote and authenticated attacker to access unauthorized files and services on the system through specially crafted web requests.
Which versions of FortiManager and FortiAnalyzer are affected by CVE-2023-25609?
FortiManager and FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, and 6.4.8 through 6.4.11 are affected by CVE-2023-25609.
How can I mitigate the CVE-2023-25609 vulnerability?
To mitigate the CVE-2023-25609 vulnerability, it is recommended to apply the necessary security patches provided by Fortinet.