CVE-2023-26204
LOWFortiSIEM <6.7 - Info Disclosure
Title source: llmDescription
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.
References (1)
Scores
CVSS v3
3.7
EPSS
0.0025
EPSS Percentile
48.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-522
CWE-256
Status
published
Affected Products (12)
fortinet/fortisiem
< 5.3.3
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
fortinet/fortisiem
Timeline
Published
Jun 13, 2023
Tracked Since
Feb 18, 2026