PT-2023-5207 · Fortinet · Fortitester

Published

2023-08-21

·

Updated

2023-09-15

·

CVE-2023-40715

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiTester versions 2.3.0 through 7.2.3
Description A cleartext storage of sensitive information issue may allow an attacker with access to the database contents to retrieve the plaintext password of external servers configured in the device. This issue is related to the storage of confidential information in an unencrypted manner, which could permit an unauthorized party to gain access to protected information.
Recommendations For FortiTester versions 2.3.0 through 7.2.3, consider restricting access to the database contents to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the configuration of external servers in the device to reduce the potential impact. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-05813
CVE-2023-40715

Affected Products

Fortitester