CVE Vulnerabilities

CVE-2023-26204

Plaintext Storage of a Password

Published: Jun 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Weakness

Storing a password in plaintext may result in a system compromise.

Affected Software

Name Vendor Start Version End Version
Fortisiem Fortinet 5.3.0 (including) 5.3.3 (including)
Fortisiem Fortinet 6.3.0 (including) 6.3.3 (including)
Fortisiem Fortinet 6.6.0 (including) 6.6.3 (including)
Fortisiem Fortinet 6.7.0 (including) 6.7.5 (including)
Fortisiem Fortinet 5.4.0 (including) 5.4.0 (including)
Fortisiem Fortinet 6.1.0 (including) 6.1.0 (including)
Fortisiem Fortinet 6.1.1 (including) 6.1.1 (including)
Fortisiem Fortinet 6.1.2 (including) 6.1.2 (including)
Fortisiem Fortinet 6.2.0 (including) 6.2.0 (including)
Fortisiem Fortinet 6.2.1 (including) 6.2.1 (including)
Fortisiem Fortinet 6.4.0 (including) 6.4.0 (including)
Fortisiem Fortinet 6.4.1 (including) 6.4.1 (including)
Fortisiem Fortinet 6.4.2 (including) 6.4.2 (including)
Fortisiem Fortinet 6.5.0 (including) 6.5.0 (including)
Fortisiem Fortinet 6.5.1 (including) 6.5.1 (including)

Potential Mitigations

References