CVE-2023-42782: Fortinet Fortianalyzer

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.

Affected products

  • Fortinet Fortianalyzer: from 6.2.0, up to and including 6.2.12; from 6.4.0, up to and including 6.4.13; from 7.0.0, up to and including 7.0.9; from 7.2.0, up to and including 7.2.3; version 7.4.0 only

Published 2023-10-10. Last modified 2026-06-17.