CVE-2023-26204

LOW

FortiSIEM <6.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Scores

CVSS v3 3.7
EPSS 0.0027
EPSS Percentile 50.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522 CWE-256
Status published
Products (12)
fortinet/fortisiem 5.4.0
fortinet/fortisiem 6.1.0
fortinet/fortisiem 6.1.1
fortinet/fortisiem 6.1.2
fortinet/fortisiem 6.2.0
fortinet/fortisiem 6.2.1
fortinet/fortisiem 6.4.0
fortinet/fortisiem 6.4.1
fortinet/fortisiem 6.4.2
fortinet/fortisiem 6.5.0
... and 2 more
Published Jun 13, 2023
Tracked Since Feb 18, 2026