Security Advisory

CVE-2023-42782

5.3
MEDIUM

Vulnerability Description

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
Published Date October 10, 2023
Official Source NIST NVD Advisory