PT-2024-3552 · Fortinet · Fortivoice

Published

2024-05-14

·

Updated

2024-05-23

·

CVE-2023-40720

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:N/A:P
Name of the Vulnerable Software and Affected Versions FortiVoice versions 7.0.0 through 7.0.1 FortiVoice versions prior to 6.4.8
Description The issue is related to an authorization bypass through a user-controlled key, allowing a remote attacker to disclose configuration SIP files by sending specially crafted HTTP or HTTPS requests. This can enable an authenticated attacker to read the SIP configuration of other users.
Recommendations For FortiVoice versions 7.0.0 through 7.0.1, update to a version outside of this range to resolve the issue. For FortiVoice versions prior to 6.4.8, update to version 6.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the SIP configuration files until a patch is available.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03857
CVE-2023-40720

Affected Products

Fortivoice