CVE-2023-44253: Informative error messages
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.
Other sources
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44253?
The severity of CVE-2023-44253 is notable as it allows unauthorized actors to enumerate sensitive information.
How do I fix CVE-2023-44253?
To fix CVE-2023-44253, upgrade to FortiManager or FortiAnalyzer version 7.4.2 or above, or 7.2.4 or above as applicable.
Which Fortinet products are affected by CVE-2023-44253?
CVE-2023-44253 affects FortiManager and FortiAnalyzer across various versions from 6.2 to 7.4.1.
Can CVE-2023-44253 lead to data breaches?
Yes, CVE-2023-44253 can potentially lead to data breaches through unauthorized information exposure.
Is there a workaround for CVE-2023-44253?
There are currently no known workarounds for CVE-2023-44253, and upgrading is recommended to mitigate risks.