CVE-2023-26204

LOW

FortiSIEM <6.7 - Info Disclosure

Title source: llm

Description

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Scores

CVSS v3 3.7
EPSS 0.0025
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-522 CWE-256
Status published

Affected Products (12)

fortinet/fortisiem < 5.3.3
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem

Timeline

Published Jun 13, 2023
Tracked Since Feb 18, 2026