CVE-2023-41676

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-23-290 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.0.0:*:*:*:*:*:*:*

History

21 Nov 2023, 01:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Fortinet
Fortinet fortisiem
References () https://fortiguard.com/psirt/FG-IR-23-290 - () https://fortiguard.com/psirt/FG-IR-23-290 - Vendor Advisory
CWE CWE-522
CPE cpe:2.3:a:fortinet:fortisiem:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*

14 Nov 2023, 18:51

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-14 18:15

Updated : 2023-12-10 15:26


NVD link : CVE-2023-41676

Mitre link : CVE-2023-41676

CVE.ORG link : CVE-2023-41676


JSON object : View

Products Affected

fortinet

  • fortisiem
CWE
CWE-522

Insufficiently Protected Credentials

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor