CVE-2024-23662

MEDIUM

FortiOS 6.4.0-6.4.15, 7.0.0-7.0.15, 7.2.0-7.2.5, 7.4.0-7.4.1 - Exposure of Sensitive Information via HTTP Requests

Title source: llm
STIX 2.1

Description

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 58.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
fortinet/fortios 6.4.0 - 7.2.6
Published Apr 09, 2024
Tracked Since Feb 18, 2026