cbcvebase.
CVE-2024-23107
published 2024-06-03

CVE-2024-23107: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and…

PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.20%
10.2th percentile
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetfortiweb
fortinetfortiweb
fortinetfortiweb6.3.0 – 6.3.23
fortinetfortiweb>= 7.0.0 < 7.0.97.0.9
fortinetfortiweb7.0.0 – 7.0.8
fortinetfortiweb>= 7.2.0 < 7.2.57.2.5
fortinetfortiweb7.2.0 – 7.2.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.