CVE-2024-52966: Disclosure of Logs of Devices not belonging to the Current ADOM from Log View
An Exposure of Sensitive Information to an Unauthorized Actor [CWE-200] in the Log View component of FortiAnalyzer may allow a local authenticated user with admin privileges to view logs of devices not belonging to the current ADOM
Other sources
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52966?
CVE-2024-52966 is classified as a medium severity vulnerability that allows exposure of sensitive information to unauthorized actors.
How do I fix CVE-2024-52966?
To resolve CVE-2024-52966, upgrade FortiAnalyzer to version 7.6.1 or later after ensuring you are running a vulnerable version.
Who is affected by CVE-2024-52966?
CVE-2024-52966 affects FortiAnalyzer versions from 6.4.0 to 7.6.0, specifically when local authenticated users have admin privileges.
What type of vulnerability is CVE-2024-52966?
CVE-2024-52966 is an Exposure of Sensitive Information vulnerability as defined by CWE-200.
What impact does CVE-2024-52966 have on security?
CVE-2024-52966 can allow a local authenticated user to view logs of devices not belonging to their current administrative domain, potentially leading to data leakage.