Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiAnalyzer version 7.4.1 or above Please upgrade to FortiAnalyzer version 7.2.4 or above AND Configure the "un-encrypted-logging" option to disable receiving syslog without encryption through UDP(514) or TCP(514). config system log setting set un-encrypted-logging disable
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-47212 | A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number. |
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-221 |
|
Wed, 18 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet fortianalyzer-bigdata
Fortinet fortimanager |
|
| CPEs | cpe:2.3:a:fortinet:fortianalyzer-bigdata:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet fortianalyzer-bigdata
Fortinet fortimanager |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-18T20:50:44.592Z
Reserved: 2023-09-14T08:37:38.656Z
Link: CVE-2023-42782
Updated: 2024-08-02T19:30:24.781Z
Status : Modified
Published: 2023-10-10T17:15:12.873
Modified: 2024-11-21T08:23:08.817
Link: CVE-2023-42782
No data.
OpenCVE Enrichment
No data.
EUVD