Medium severity6.5NVD Advisory· Published Oct 20, 2023· Updated Jun 17, 2026
CVE-2023-44256
CVE-2023-44256
Description
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.4.8,<=6.4.13
- cpe:2.3:a:fortinet:fortianalyzer:7.4.0:*:*:*:*:*:*:*
- (no CPE)range: 7.4.0, 7.2.0-7.2.3, <7.0.8
- (no CPE)range: 7.4.0
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.8
- cpe:2.3:a:fortinet:fortimanager:7.4.0:*:*:*:*:*:*:*
- (no CPE)range: 7.4.0, 7.2.0-7.2.3, <7.0.8
- (no CPE)range: 7.4.0
Patches
Vulnerability mechanics
References
2- github.com/orangecertcc/security-research/security/advisories/GHSA-2hc5-p5mc-8vrhnvdExploitThird Party Advisory
- fortiguard.com/psirt/FG-IR-19-039nvdVendor Advisory
News mentions
0No linked articles in our index yet.