An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
History

Tue, 17 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortiweb
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiweb

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-08-01T22:51:11.271Z

Reserved: 2024-01-11T16:29:07.979Z

Link: CVE-2024-23107

cve-icon Vulnrichment

Updated: 2024-08-01T22:51:11.271Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-03T08:15:08.837

Modified: 2024-12-17T16:51:35.250

Link: CVE-2024-23107

cve-icon Redhat

No data.