A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortianalyzer | Fortinet | 6.2.0 (including) | 6.2.12 (including) |
Fortianalyzer | Fortinet | 6.4.0 (including) | 6.4.13 (including) |
Fortianalyzer | Fortinet | 7.0.0 (including) | 7.0.9 (including) |
Fortianalyzer | Fortinet | 7.2.0 (including) | 7.2.3 (including) |
Fortianalyzer | Fortinet | 7.4.0 (including) | 7.4.0 (including) |