cbcvebase.
CVE-2023-22636
published 2023-02-27

CVE-2023-22636: An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker…

PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.16%
5.8th percentile
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.

Affected

4 ranges
VendorProductVersion rangeFixed in
fortinetfortiweb
fortinetfortiweb6.3.6 – 6.3.21
fortinetfortiweb6.4.0 – 6.4.2
fortinetfortiweb7.0.0 – 7.0.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.