CVE-2024-23666

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData 
at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
7.1 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:X
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
fortinetfortianalyzer
6.4.0 ≤
𝑥
< 6.4.15
fortinetfortianalyzer
7.0.0 ≤
𝑥
< 7.0.13
fortinetfortianalyzer
7.2.0 ≤
𝑥
< 7.2.6
fortinetfortianalyzer
7.4.0 ≤
𝑥
< 7.4.3
fortinetfortianalyzer_big_data
6.2.1 ≤
𝑥
< 7.2.7
fortinetfortianalyzer_big_data
7.4.0
fortinetfortimanager
6.4.0 ≤
𝑥
< 6.4.15
fortinetfortimanager
7.0.0 ≤
𝑥
< 7.0.13
fortinetfortimanager
7.2.0 ≤
𝑥
< 7.2.6
fortinetfortimanager
7.4.0 ≤
𝑥
< 7.4.3
𝑥
= Vulnerable software versions