PT-2026-32649 · Fortinet · Fortindr+1
Published
2026-04-14
·
Updated
2026-04-19
·
CVE-2024-23104
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FortiNDR version 7.6.0
FortiNDR versions 7.4.0 through 7.4.8
FortiNDR version 7.2
FortiNDR version 7.1
FortiNDR version 7.0
FortiVoice versions 7.0.0 through 7.0.1
Description
An exposure of sensitive information in the graphical user interface may allow a remote authenticated attacker with at least read-only permission on system maintenance to gain unauthorized access to backup information by sending specially crafted HTTP requests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortindr
Fortivoice