CVE Vulnerabilities

CVE-2023-41676

Insufficiently Protected Credentials

Published: Nov 14, 2023 | Modified: Nov 21, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Fortisiem Fortinet 6.7.0 (including) 6.7.5 (including)
Fortisiem Fortinet 7.0.0 (including) 7.0.0 (including)

Potential Mitigations

References