CVE Vulnerabilities

CVE-2023-26204

Plaintext Storage of a Password

Published: Jun 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

Name Vendor Start Version End Version
Fortisiem Fortinet 5.3.0 (including) 5.3.3 (including)
Fortisiem Fortinet 6.3.0 (including) 6.3.3 (including)
Fortisiem Fortinet 6.6.0 (including) 6.6.3 (including)
Fortisiem Fortinet 6.7.0 (including) 6.7.5 (including)
Fortisiem Fortinet 5.4.0 (including) 5.4.0 (including)
Fortisiem Fortinet 6.1.0 (including) 6.1.0 (including)
Fortisiem Fortinet 6.1.1 (including) 6.1.1 (including)
Fortisiem Fortinet 6.1.2 (including) 6.1.2 (including)
Fortisiem Fortinet 6.2.0 (including) 6.2.0 (including)
Fortisiem Fortinet 6.2.1 (including) 6.2.1 (including)
Fortisiem Fortinet 6.4.0 (including) 6.4.0 (including)
Fortisiem Fortinet 6.4.1 (including) 6.4.1 (including)
Fortisiem Fortinet 6.4.2 (including) 6.4.2 (including)
Fortisiem Fortinet 6.5.0 (including) 6.5.0 (including)
Fortisiem Fortinet 6.5.1 (including) 6.5.1 (including)

Potential Mitigations

References