CVE Vulnerabilities

CVE-2023-26204

Plaintext Storage of a Password

Published: Jun 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
FortisiemFortinet5.3.0 (including)5.3.3 (including)
FortisiemFortinet6.3.0 (including)6.3.3 (including)
FortisiemFortinet6.6.0 (including)6.6.3 (including)
FortisiemFortinet6.7.0 (including)6.7.5 (including)
FortisiemFortinet5.4.0 (including)5.4.0 (including)
FortisiemFortinet6.1.0 (including)6.1.0 (including)
FortisiemFortinet6.1.1 (including)6.1.1 (including)
FortisiemFortinet6.1.2 (including)6.1.2 (including)
FortisiemFortinet6.2.0 (including)6.2.0 (including)
FortisiemFortinet6.2.1 (including)6.2.1 (including)
FortisiemFortinet6.4.0 (including)6.4.0 (including)
FortisiemFortinet6.4.1 (including)6.4.1 (including)
FortisiemFortinet6.4.2 (including)6.4.2 (including)
FortisiemFortinet6.5.0 (including)6.5.0 (including)
FortisiemFortinet6.5.1 (including)6.5.1 (including)

Potential Mitigations

References