CVE Vulnerabilities

CVE-2023-42782

Insufficient Verification of Data Authenticity

Published: Oct 10, 2023 | Modified: Nov 07, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 6.2.0 (including) 6.2.12 (including)
Fortianalyzer Fortinet 6.4.0 (including) 6.4.13 (including)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.9 (including)
Fortianalyzer Fortinet 7.2.0 (including) 7.2.3 (including)
Fortianalyzer Fortinet 7.4.0 (including) 7.4.0 (including)

References