PT-2024-19670 · Fortinet · Fortiweb

Published

2024-06-03

·

Updated

2024-12-17

·

CVE-2024-23107

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiWeb versions 6.3 and all versions prior to 7.0.8 FortiWeb versions 7.2.4 and below FortiWeb version 7.4.0
Description The issue allows an authenticated attacker to read password hashes of other administrators via CLI commands. This is due to an exposure of sensitive information to an unauthorized actor.
Recommendations For FortiWeb version 7.4.0, update to a version that fixes this issue. For FortiWeb versions 7.2.4 and below, update to a version that fixes this issue. For FortiWeb versions prior to 7.0.8, update to a version that fixes this issue. For FortiWeb versions 6.3, update to a version that fixes this issue. As a temporary workaround, consider restricting access to CLI commands until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-23107

Affected Products

Fortiweb