CVE-2023-46713: Medium severity fortinet fortiweb vulnerability
Published Dec 13, 2023
·Updated
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
Affected Software
5 affected components
Fortinet FortiWeb>=6.2.0<=6.2.8
Fortinet FortiWeb>=6.3.0<=6.3.23
Fortinet FortiWeb>=7.0.0<=7.0.9
Fortinet FortiWeb>=7.2.0<=7.2.5
Fortinet FortiWeb=7.4.0
Remediation
Information
Please upgrade to FortiWeb version 7.4.1 or above
Please upgrade to FortiWeb version 7.2.6 or above
Event History
Dec 13, 2023
CVE Published
06:41 AM
Data Sourced
06:41 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46713?
CVE-2023-46713 has been classified with a moderate severity level due to its potential impact on log integrity.
2
How do I fix CVE-2023-46713?
To mitigate CVE-2023-46713, upgrade Fortinet FortiWeb to versions 6.2.9, 6.3.24, 7.0.10, 7.2.6, or 7.4.1 or later.
3
Which versions of FortiWeb are affected by CVE-2023-46713?
CVE-2023-46713 affects Fortinet FortiWeb versions 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5, and 7.4.0.
4
What type of vulnerability is CVE-2023-46713?
CVE-2023-46713 is classified as an improper output neutralization for logs vulnerability.
5
Can CVE-2023-46713 allow attackers to modify logs?
Yes, CVE-2023-46713 may allow attackers to forge traffic logs through crafted URLs.