CVE-2023-42787: Fortinet Fortianalyzer
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
Affected products
- Fortinet Fortianalyzer: from 6.2.0, up to and including 6.2.12; from 6.4.0, up to and including 6.4.13; from 7.0.0, up to and including 7.0.9; from 7.2.0, up to and including 7.2.3; version 7.4.0 only
- Fortinet FortiManager: from 6.2.0, up to and including 6.2.12; from 6.4.0, up to and including 6.4.13; from 7.0.0, up to and including 7.0.9; from 7.2.0, up to and including 7.2.3; version 7.4.0 only
Published 2023-10-10. Last modified 2026-08-12.