CVE-2024-23662Sensitive Information Exposure in Fortinet Fortios

Severity
7.5HIGHNVD
CNA5.3
EPSS
0.4%
top 41.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 9

Description

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/fortios6.4.07.2.6+1
CVEListV5fortinet/fortios7.4.07.4.1+3

🔴Vulnerability Details

2
GHSA
GHSA-29wp-xqwp-4vqr: An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 72024-04-09
CVEList
CVE-2024-23662: An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 72024-04-09

📋Vendor Advisories

1
Fortinet
Web server ETag exposure2024-04-09
CVE-2024-23662 — Sensitive Information Exposure | cvebase