CVE-2023-40720
published 2024-05-14CVE-2023-40720: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an…
PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHINAL
EPSS
0.85%
53.8th percentile
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | 6.0.0 – 6.0.12 | — |
| fortinet | fortivoice | 6.4.0 – 6.4.8 | — |
| fortinet | fortivoice | 7.0.0 – 7.0.1 | — |
| fortinet | fortivoiceentreprise | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug...
vendor_fortinet·2024-05-14·CVSS 7.1
CVE-2023-40720 [HIGH] CWE-639 An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug...
FG-IR-23-282: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug...
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
CVEs: CVE-2023-40720
CWEs: CWE-639
CVSS: 7.1 (high)
Affected products: FortiVoice, FortiVoiceEntreprise
GHSA
GHSA-wr9w-6wcp-7m3p: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7
ghsa_unreviewed·2024-05-14
CVE-2023-40720 [HIGH] CWE-639 GHSA-wr9w-6wcp-7m3p: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-14
Published