CVE-2023-44255: Lack of capacity to filter logs by administrator access
An Exposure of personal information to an unauthorized actor [CWE-359] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
Other sources
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44255?
CVE-2023-44255 has been classified as a significant vulnerability due to its potential to expose sensitive event logs to unauthorized actors.
How do I fix CVE-2023-44255?
To mitigate CVE-2023-44255, upgrade FortiManager and FortiAnalyzer to version 7.4.3 or later.
Which Fortinet products are affected by CVE-2023-44255?
CVE-2023-44255 affects several versions of FortiManager and FortiAnalyzer, specifically versions prior to 7.4.3.
Who can exploit CVE-2023-44255?
CVE-2023-44255 can be exploited by a privileged attacker with administrative read permissions.
What type of data exposure does CVE-2023-44255 involve?
CVE-2023-44255 involves the exposure of event logs from one administrative domain to another.