CVE-2023-44249: Authorization bypass via key value controlled by user
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiManager & FortiAnalyzer may allow a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
Other sources
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-44249.
What is the severity of CVE-2023-44249?
The severity of CVE-2023-44249 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2023-44249?
Fortinet FortiManager versions 7.4.0 and before 7.2.3, and FortiAnalyzer versions 7.4.0 and before 7.2.3 are affected by CVE-2023-44249.
How does CVE-2023-44249 work?
CVE-2023-44249 is an authorization bypass vulnerability that allows a remote attacker with low privileges to read sensitive information through crafted HTTP requests.
Is there a fix available for CVE-2023-44249?
Yes, it is recommended to update to Fortinet FortiManager version 7.4.0 or 7.2.3, and FortiAnalyzer version 7.4.0 or 7.2.3 to fix CVE-2023-44249.