CVE-2023-44256: Server side request forgery on fortiview top threats report generation feature.
A server-side request forgery vulnerability [CWE-918] in FortiAnalyzer and FortiManager may allow a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.
Other sources
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44256?
The severity of CVE-2023-44256 is medium with a CVSS score of 6.5.
Which versions of Fortinet FortiAnalyzer are affected by CVE-2023-44256?
Fortinet FortiAnalyzer versions 7.4.0, 7.2.0 through 7.2.3, 7.0.2 through 7.0.8, and 6.4.8 through 6.4.13 are affected by CVE-2023-44256.
Which versions of Fortinet FortiManager are affected by CVE-2023-44256?
Fortinet FortiManager versions 7.4.0, 7.2.0 through 7.2.3, and 7.0.0 through 7.0.8 are affected by CVE-2023-44256.
What is the vulnerability type of CVE-2023-44256?
CVE-2023-44256 is a server-side request forgery vulnerability (CWE-918).
What is the impact of CVE-2023-44256?
CVE-2023-44256 allows a remote attacker with low privileges to view sensitive data from internal systems.