CVE-2024-52966: An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information...

2.2 CVSS

Description

An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.

Classification

CVE ID: CVE-2024-52966

CVSS Base Severity: LOW

CVSS Base Score: 2.2

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C

Affected Products

Vendor: Fortinet

Product: FortiAnalyzer

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.94% (scored less or equal to compared to others)

EPSS Date: 2025-03-12 (when was this score calculated)

References

https://fortiguard.fortinet.com/psirt/FG-IR-24-422

Timeline