CVE-2023-26204
published 2023-06-13CVE-2023-26204: A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.43%
35.1th percentile
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | 5.3.0 – 5.3.3 | — |
| fortinet | fortisiem | 6.1.0 – 6.1.2 | — |
| fortinet | fortisiem | 6.2.0 – 6.2.1 | — |
| fortinet | fortisiem | 6.3.0 – 6.3.3 | — |
| fortinet | fortisiem | 6.4.0 – 6.4.2 | — |
| fortinet | fortisiem | 6.5.0 – 6.5.1 | — |
| fortinet | fortisiem | 6.6.0 – 6.6.3 | — |
| fortinet | fortisiem | 6.7.0 – 6.7.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An attacker who gains read access to the FortiSIEM user database (DB) can extract plaintext admin credentials and use them to authenticate to the device GUI — monitor for unexpected or anomalous admin GUI logins, especially following any DB-level access. ↗
- →Audit FortiSIEM user DB storage for plaintext password fields (CWE-256/CWE-522); presence of cleartext credentials in the DB is the primary indicator of vulnerable configuration. ↗
- ·All listed FortiSIEM versions store admin passwords in plaintext within the user DB, meaning any attacker with DB read access (e.g., via SQL injection, backup file exposure, or insider access) immediately obtains usable credentials — no cracking required. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8v4-f4rj-qhhf: A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6
ghsa_unreviewed·2023-06-13
CVE-2023-26204 [CRITICAL] CWE-256 GHSA-v8v4-f4rj-qhhf: A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.
Fortinet
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi...
vendor_fortinet·2023-06-13·CVSS 3.7
CVE-2023-26204 [LOW] CWE-256 A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi...
FG-IR-21-141: A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi...
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.
CVEs: CVE-2023-26204
CWEs: CWE-256, CWE-522
CVSS: 3.7 (low)
Affected products: FortiSIEM
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-13
Published