Lucene search

K
nvd[email protected]NVD:CVE-2023-26204
HistoryJun 13, 2023 - 9:15 a.m.

CVE-2023-26204

2023-06-1309:15:16
CWE-256
CWE-522
web.nvd.nist.gov
2
plaintext storage vulnerability
fortisiem
multiple versions
user database
impersonation
gui access

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

54.4%

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allowΒ an attacker able to access user DB content to impersonate any admin user on the device GUI.

Affected configurations

Nvd
Node
fortinetfortisiemRange5.3.0–5.3.3
OR
fortinetfortisiemRange6.3.0–6.3.3
OR
fortinetfortisiemRange6.6.0–6.6.3
OR
fortinetfortisiemRange6.7.0–6.7.5
OR
fortinetfortisiemMatch5.4.0
OR
fortinetfortisiemMatch6.1.0
OR
fortinetfortisiemMatch6.1.1
OR
fortinetfortisiemMatch6.1.2
OR
fortinetfortisiemMatch6.2.0
OR
fortinetfortisiemMatch6.2.1
OR
fortinetfortisiemMatch6.4.0
OR
fortinetfortisiemMatch6.4.1
OR
fortinetfortisiemMatch6.4.2
OR
fortinetfortisiemMatch6.5.0
OR
fortinetfortisiemMatch6.5.1
VendorProductVersionCPE
fortinetfortisiem*cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
fortinetfortisiem5.4.0cpe:2.3:a:fortinet:fortisiem:5.4.0:*:*:*:*:*:*:*
fortinetfortisiem6.1.0cpe:2.3:a:fortinet:fortisiem:6.1.0:*:*:*:*:*:*:*
fortinetfortisiem6.1.1cpe:2.3:a:fortinet:fortisiem:6.1.1:*:*:*:*:*:*:*
fortinetfortisiem6.1.2cpe:2.3:a:fortinet:fortisiem:6.1.2:*:*:*:*:*:*:*
fortinetfortisiem6.2.0cpe:2.3:a:fortinet:fortisiem:6.2.0:*:*:*:*:*:*:*
fortinetfortisiem6.2.1cpe:2.3:a:fortinet:fortisiem:6.2.1:*:*:*:*:*:*:*
fortinetfortisiem6.4.0cpe:2.3:a:fortinet:fortisiem:6.4.0:*:*:*:*:*:*:*
fortinetfortisiem6.4.1cpe:2.3:a:fortinet:fortisiem:6.4.1:*:*:*:*:*:*:*
fortinetfortisiem6.4.2cpe:2.3:a:fortinet:fortisiem:6.4.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

54.4%

Related for NVD:CVE-2023-26204