An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortisiem | Fortinet | 6.7.0 (including) | 6.7.5 (including) |
Fortisiem | Fortinet | 7.0.0 (including) | 7.0.0 (including) |