« Volver al listado

CVE-2023-44248

Estado: ModificadaMedia (5.5)—

An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-44248",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-44248",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-30T18:11:43.737058Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@fortinet.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@fortinet.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:fortinet:fortiedrcollectorwindows:5.0.2:*:*:*:*:*:*:*",
            "cpe:2.3:a:fortinet:fortiedrcollectorwindows:5.0.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:fortinet:fortiedrcollectorwindows:5.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "Fortinet",
          "product": "FortiEDR CollectorWindows",
          "versions": [
            {
              "status": "affected",
              "version": "5.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "5.0.2"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-14T18:15:54.470",
  "references": [
    {
      "url": "https://fortiguard.com/psirt/FG-IR-23-306",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@fortinet.com"
    },
    {
      "url": "https://fortiguard.com/psirt/FG-IR-23-306",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@fortinet.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de control de acceso inadecuado [CWE-284] en FortiEDRCollectorWindows versión 5.2.0.4549 y anteriores, 5.0.3.1007 y anteriores, 4.0 puede permitir que un atacante local impida que el servicio recopilador se inicie en el siguiente reinicio del sistema alterando algunas claves de registro del servicio."
    }
  ],
  "lastModified": "2026-06-17T06:27:12.837",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fortinet:fortiedr:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A10D784-1ED4-46CC-AEB0-F006F8B0E16E",
              "versionEndIncluding": "5.0.3.1007",
              "versionStartIncluding": "5.0.3"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiedr:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AF2B177-B287-4C8F-B1F4-42D3051D5EC7",
              "versionEndIncluding": "5.2.0.4549",
              "versionStartIncluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiedr:4.0.0:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "895977DC-C7C4-422F-BCAC-B2B46582A912"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@fortinet.com"
}