PT-2023-1861 · Fortinet · Fortianalyzer
Publicado
2023-03-07
·
Atualizado
2023-03-14
·
CVE-2023-23776
CVSS v3.1
4.6
Média
| Vetor | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
FortiAnalyzer versions 6.4.0 through 6.4.10
FortiAnalyzer versions 7.0.0 through 7.0.4
FortiAnalyzer versions 7.2.0 through 7.2.1
Description
The issue is related to insufficient protection of passwords, allowing a remote authenticated attacker to read the client machine password in plain text in a heartbeat response when a log-fetch request is made from the FortiAnalyzer. This may enable an unauthorized actor to gain access to sensitive information.
Recommendations
For FortiAnalyzer versions 6.4.0 through 6.4.10, update to a version that fixes the issue.
For FortiAnalyzer versions 7.0.0 through 7.0.4, update to a version that fixes the issue.
For FortiAnalyzer versions 7.2.0 through 7.2.1, update to a version that fixes the issue.
As a temporary workaround, consider restricting access to the log-fetch request functionality until a patch is available.
Correção
Cleartext Storage of Sensitive Information
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Fortianalyzer