PT-2026-32649 · Fortinet · Fortindr+1

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2024-23104

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiNDR version 7.6.0 FortiNDR versions 7.4.0 through 7.4.8 FortiNDR version 7.2 FortiNDR version 7.1 FortiNDR version 7.0 FortiVoice versions 7.0.0 through 7.0.1
Description An exposure of sensitive information in the graphical user interface may allow a remote authenticated attacker with at least read-only permission on system maintenance to gain unauthorized access to backup information by sending specially crafted HTTP requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-05554
CVE-2024-23104

Affected Products

Fortindr
Fortivoice