Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.

CVSS 1 Total

ScoreSeverityVersionVector String
5.0MEDIUM3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C

Product Status

Learn more

Versions 5 Total

Default Status: unaffected

affected

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.

Authorized Data Publishers