CVE-2023-41676

MEDIUM

FortiSIEM <7.0.0 - Info Disclosure

Title source: llm

Description

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

Scores

CVSS v3 4.3
EPSS 0.0033
EPSS Percentile 55.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-522 CWE-200
Status published

Affected Products (2)

fortinet/fortisiem < 6.7.5
fortinet/fortisiem

Timeline

Published Nov 14, 2023
Tracked Since Feb 18, 2026