CVE-2024-23107
published 2024-06-03CVE-2024-23107: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.20%
10.2th percentile
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 6.3.0 – 6.3.23 | — |
| fortinet | fortiweb | >= 7.0.0 < 7.0.9 | 7.0.9 |
| fortinet | fortiweb | 7.0.0 – 7.0.8 | — |
| fortinet | fortiweb | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | fortiweb | 7.2.0 – 7.2.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version...
vendor_fortinet·2024-06-03·CVSS 5.5
CVE-2024-23107 [MEDIUM] CWE-200 An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version...
FG-IR-23-191: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version...
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
CVEs: CVE-2024-23107
CWEs: CWE-200
CVSS: 5.5 (medium)
Affected products: FortiWeb
GHSA
GHSA-qw8c-jpj8-7mxc: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7
ghsa_unreviewed·2024-06-03
CVE-2024-23107 [MEDIUM] CWE-200 GHSA-qw8c-jpj8-7mxc: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-03
Published