An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2024-06-03T07:55:21.908Z

Updated: 2024-08-01T22:51:11.271Z

Reserved: 2024-01-11T16:29:07.979Z

Link: CVE-2024-23107

cve-icon Vulnrichment

Updated: 2024-08-01T22:51:11.271Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-03T08:15:08.837

Modified: 2024-11-21T08:56:56.640

Link: CVE-2024-23107

cve-icon Redhat

No data.