Sploitus

CVE-2023-42787

No indexed exploits for CVE-2023-42787 yet

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.

Affected products
Fortianalyzer, Fortimanager
Fortinet Fortianalyzer
≤ 6.2.12, 6.4.13, 7.0.9, 7.2.3, 7.4.0
Fortinet Fortimanager
≤ 6.2.12, 6.4.13, 7.0.9, 7.2.3, 7.4.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
1.4% (69th percentile)
Weakness
CWE-602
NVD status
Modified
Published
2023-10-10

Fix

Please upgrade to FortiManager version 7.4.1 or above Please upgrade to FortiManager version 7.2.4 or above Please upgrade to FortiAnalyzer version 7.4.1 or above Please upgrade to FortiAnalyzer version 7.2.4 or above

CVE-2023-42787 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-42787 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-42787 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.