First published: Mon Oct 07 2024(Updated: )
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager Administrative Domain (ADOM) may allow a remote authenticated attacker assigned to an ADOM to access device summary of other ADOMs via crafted HTTP requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | >=7.4.0<=7.4.2 | |
Fortinet FortiManager | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | >=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-23-472 is categorized as critical due to the potential for unauthorized access to sensitive information in FortiManager.
To fix FG-IR-23-472, update FortiManager to versions 7.4.3 or 7.2.6 or later, as applicable.
FortiManager versions 7.4.0 to 7.4.2 and 7.2.0 to 7.2.5 are affected by FG-IR-23-472.
The FG-IR-23-472 vulnerability can be exploited by remote authenticated attackers assigned to an Administrative Domain (ADOM).
FG-IR-23-472 is classified as an exposure of sensitive information vulnerability, specifically categorized under CWE-200.