Description
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiTester version 7.3.0 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45269 | A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-465 |
|
History
Tue, 24 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-24T19:56:35.906Z
Reserved: 2023-08-21T09:03:44.315Z
Link: CVE-2023-40715
Updated: 2024-08-02T18:38:51.090Z
Status : Modified
Published: 2023-09-13T13:15:09.320
Modified: 2024-11-21T08:20:01.023
Link: CVE-2023-40715
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD