CVE-2024-23666: Readonly users could run some sensitive operations
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
Other sources
A client-side enforcement of server-side security vulnerability [CWE-602] in FortiAnalyzer may allow an authenticated attacker with at least read-only permission to execute sensitive operations via crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23666?
The severity of CVE-2024-23666 is currently classified as critical due to its potential impact on exploitation of client-side enforcement failures.
How do I fix CVE-2024-23666?
To fix CVE-2024-23666, update FortiAnalyzer to version 7.4.3 or higher, FortiManager to 7.4.3 or higher, and FortiAnalyzer-BigData to at least 7.4.1.
Which Fortinet products are affected by CVE-2024-23666?
CVE-2024-23666 affects FortiAnalyzer, FortiManager, and FortiAnalyzer-BigData versions ranging from 6.2.5 to 7.4.2.
Is CVE-2024-23666 being actively exploited?
As of the latest reports, there is no indication that CVE-2024-23666 is being actively exploited in the wild.
What is the nature of the vulnerability in CVE-2024-23666?
CVE-2024-23666 is a client-side enforcement of server-side security vulnerability that may allow unauthorized access to sensitive data.