CVE-2024-33506

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
Configurations

No configuration.

History

10 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de exposición de información confidencial a un actor no autorizado [CWE-200] en FortiManager 7.4.2 y anteriores, 7.2.5 y anteriores, 7.0.12 y anteriores permite que un atacante remoto autenticado asignado a un dominio administrativo (ADOM) acceda al resumen del dispositivo de ADOM no autorizados a través de solicitudes HTTP manipuladas.

08 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-08 15:15

Updated : 2024-10-10 12:56


NVD link : CVE-2024-33506

Mitre link : CVE-2024-33506

CVE.ORG link : CVE-2024-33506


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor