CVE-2023-44256
MEDIUMFortiAnalyzer/FortiManager SSRF via Crafted HTTP Request
Title source: llmDescription
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.
References (2)
Core 2
Core References
Vendor Advisory
https://fortiguard.com/psirt/FG-IR-19-039
Exploit, Third Party Advisory
https://github.com/orangecertcc/security-research/security/advisories/GHSA-2hc5-p5mc-8vrh
Scores
CVSS v3
6.5
EPSS
0.0055
EPSS Percentile
68.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
CWE-918
Status
published
Products (4)
fortinet/fortianalyzer
7.4.0
fortinet/fortianalyzer
6.4.8 - 6.4.13
fortinet/fortimanager
7.4.0
fortinet/fortimanager
7.0.0 - 7.0.8
Published
Oct 20, 2023
Tracked Since
Feb 18, 2026