QID 379128

Date Published: 2023-12-20

QID 379128: Fortinet FortiAnalyzer and FortiManager - Server-Side Request Forgery (SSRF) Vulnerability (FG-IR-19-039)

A server-side request forgery vulnerability [CWE-918] in FortiAnalyzer and FortiManager may allow a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.

Affected Products:
FortiManager 7.4.0
FortiManager 7.2.0 through 7.2.3
FortiManager 7.0.0 through 7.0.8
FortiAnalyzer 7.4.0
FortiAnalyzer 7.2.0 through 7.2.3
FortiAnalyzer 7.0.2 through 7.0.8
FortiAnalyzer 6.4.8 through 6.4.13

QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.

Successful exploitation of this vulnerability may allow a remote attacker with low privileges to view sensitive data from internal servers.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-19-039

    Vendor References

    CVEs related to QID 379128

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-19-039 URL Logo www.fortiguard.com/psirt/FG-IR-19-039