Lucene search

K
cveFortinetCVE-2023-26204
HistoryJun 13, 2023 - 9:15 a.m.

CVE-2023-26204

2023-06-1309:15:16
CWE-256
CWE-522
fortinet
web.nvd.nist.gov
41
cve-2023-26204
plaintext storage
password vulnerability
cwe-256
fortisiem
nvd
information security

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

54.4%

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allowΒ an attacker able to access user DB content to impersonate any admin user on the device GUI.

Affected configurations

Nvd
Node
fortinetfortisiemRange5.3.0–5.3.3
OR
fortinetfortisiemRange6.3.0–6.3.3
OR
fortinetfortisiemRange6.6.0–6.6.3
OR
fortinetfortisiemRange6.7.0–6.7.5
OR
fortinetfortisiemMatch5.4.0
OR
fortinetfortisiemMatch6.1.0
OR
fortinetfortisiemMatch6.1.1
OR
fortinetfortisiemMatch6.1.2
OR
fortinetfortisiemMatch6.2.0
OR
fortinetfortisiemMatch6.2.1
OR
fortinetfortisiemMatch6.4.0
OR
fortinetfortisiemMatch6.4.1
OR
fortinetfortisiemMatch6.4.2
OR
fortinetfortisiemMatch6.5.0
OR
fortinetfortisiemMatch6.5.1
VendorProductVersionCPE
fortinetfortisiem*cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
fortinetfortisiem5.4.0cpe:2.3:a:fortinet:fortisiem:5.4.0:*:*:*:*:*:*:*
fortinetfortisiem6.1.0cpe:2.3:a:fortinet:fortisiem:6.1.0:*:*:*:*:*:*:*
fortinetfortisiem6.1.1cpe:2.3:a:fortinet:fortisiem:6.1.1:*:*:*:*:*:*:*
fortinetfortisiem6.1.2cpe:2.3:a:fortinet:fortisiem:6.1.2:*:*:*:*:*:*:*
fortinetfortisiem6.2.0cpe:2.3:a:fortinet:fortisiem:6.2.0:*:*:*:*:*:*:*
fortinetfortisiem6.2.1cpe:2.3:a:fortinet:fortisiem:6.2.1:*:*:*:*:*:*:*
fortinetfortisiem6.4.0cpe:2.3:a:fortinet:fortisiem:6.4.0:*:*:*:*:*:*:*
fortinetfortisiem6.4.1cpe:2.3:a:fortinet:fortisiem:6.4.1:*:*:*:*:*:*:*
fortinetfortisiem6.4.2cpe:2.3:a:fortinet:fortisiem:6.4.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "vendor": "Fortinet",
    "product": "FortiSIEM",
    "defaultStatus": "unaffected",
    "versions": [
      {
        "versionType": "semver",
        "version": "6.7.0",
        "lessThanOrEqual": "6.7.5",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.6.0",
        "lessThanOrEqual": "6.6.3",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.5.0",
        "lessThanOrEqual": "6.5.1",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.4.0",
        "lessThanOrEqual": "6.4.2",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.3.0",
        "lessThanOrEqual": "6.3.3",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.2.0",
        "lessThanOrEqual": "6.2.1",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.1.0",
        "lessThanOrEqual": "6.1.2",
        "status": "affected"
      },
      {
        "version": "5.4.0",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "5.3.0",
        "lessThanOrEqual": "5.3.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

54.4%

Related for CVE-2023-26204