Headline
CVE-2023-25609: Fortiguard
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
** PSIRT Advisories**
FortiManager & FortiAnalyzer - SSRF in FortiGuard Outbreak feature
Summary
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
Affected Products
FortiAnalyzer version 7.2.0 through 7.2.1
FortiAnalyzer version 7.0.0 through 7.0.6
FortiAnalyzer version 6.4.8 through 6.4.11
FortiManager version 7.2.0 through 7.2.1
FortiManager version 7.0.0 through 7.0.6
FortiManager version 6.4.8 through 6.4.11
Solutions
Please upgrade to FortiAnalyzer version 7.2.2 or above
Please upgrade to FortiAnalyzer version 7.0.7 or above
Please upgrade to FortiAnalyzer version 6.4.12 or above
Please upgrade to FortiManager version 7.2.2 or above
Please upgrade to FortiManager version 7.0.7 or above
Please upgrade to FortiManager version 6.4.12 or above
Timeline
2023-06-09: Initial publication