FG-IR-23-267: Lack of capacity to filter logs by administrator access
An Exposure of personal information to an unauthorized actor [CWE-359] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-267?
The severity of FG-IR-23-267 is classified as high due to the exposure of personal information to unauthorized actors.
How do I fix FG-IR-23-267?
To mitigate FG-IR-23-267, upgrade FortiManager and FortiAnalyzer to version 7.4.3 or apply the necessary updates for affected versions.
Which products are affected by FG-IR-23-267?
FG-IR-23-267 affects FortiAnalyzer, FortiAnalyzer-BigData, and FortiManager across several versions.
What type of vulnerability is FG-IR-23-267?
FG-IR-23-267 is an exposure of personal information to an unauthorized actor, categorized under CWE-359.
Can a privileged attacker exploit FG-IR-23-267?
Yes, a privileged attacker with administrative read permissions can exploit FG-IR-23-267 to read event logs of another ADOM.