CVE-2023-22636
published 2023-02-27CVE-2023-22636: An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.16%
5.8th percentile
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 6.3.6 – 6.3.21 | — |
| fortinet | fortiweb | 6.4.0 – 6.4.2 | — |
| fortinet | fortiweb | 7.0.0 – 7.0.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r8gh-fx77-763f: An unauthorized configuration download vulnerability in FortiWeb 6
ghsa_unreviewed·2023-02-27
CVE-2023-22636 [LOW] GHSA-r8gh-fx77-763f: An unauthorized configuration download vulnerability in FortiWeb 6
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.
Fortinet
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 thr...
vendor_fortinet·2023-02-27·CVSS 7.0
CVE-2023-22636 [HIGH] CWE-285 An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 thr...
FG-IR-22-460: An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 thr...
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.
CVEs: CVE-2023-22636
CWEs: CWE-285
CVSS: 7.0 (high)
Affected products: FortiWeb
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-27
Published