CVE-2023-26206 PUBLISHED CVSS 4.699999809265137 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.

EPSS 0.07% · 21.1th percentile

Risk Scores

CVSS v3.1
4.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:P/RL:X/RC:C
EPSS Score
0.07%
21.1th percentile

Affected Products

VendorProductVersions
fortinetfortinac7.2.0, 9.4.0, 9.2.0
FortinetFortiNAC9.4.0, 9.2.0, 9.1.0
FortinetFortiAnalyzer6.4.0, 6.2.0, 7.0.0
FortinetFortiManager6.2.0, 6.4.0, 7.0.0

Timeline

References

Open in Interactive Console →