First published: Tue Feb 11 2025(Updated: )
An Exposure of Sensitive Information to an Unauthorized Actor [CWE-200] in the Log View component of FortiAnalyzer may allow a local authenticated user with admin privileges to view logs of devices not belonging to the current ADOM
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | =. | |
Fortinet FortiAnalyzer | >=7.4.0<=7.4.4 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.7 | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-422 falls under a critical category due to exposure of sensitive information.
To fix FG-IR-24-422, update FortiAnalyzer to version 7.6.1 or higher, or ensure you are on a remedy version for older releases.
FG-IR-24-422 affects local authenticated users with admin privileges on FortiAnalyzer devices running vulnerable versions.
FG-IR-24-422 is classified as an Exposure of Sensitive Information to an Unauthorized Actor as per CWE-200.
FG-IR-24-422 affects various versions of FortiAnalyzer, specifically those below 7.6.1, 7.4.5, and 7.2.8.