Vulnerability Description
An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiedr | >= 5.0.3, <= 5.0.3.1007 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-23-306Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-23-306Vendor Advisory
FAQ
What is CVE-2023-44248?
CVE-2023-44248 is a vulnerability with a CVSS score of 4.4 (MEDIUM). An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service t...
How severe is CVE-2023-44248?
CVE-2023-44248 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-44248?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiedr.