Description
Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to FortiAIOps version 2.0.1 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24977 | Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] in FortiAIOps version 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files. |
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-072 |
|
History
Fri, 09 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] in FortiAIOps version 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files. | Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files. |
Mon, 09 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiaiops |
|
| CPEs | cpe:2.3:a:fortinet:fortiaiops:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortiaiops |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-01-09T16:34:54.891Z
Reserved: 2024-02-26T14:46:31.335Z
Link: CVE-2024-27784
Updated: 2024-08-02T00:41:55.221Z
Status : Modified
Published: 2024-07-09T16:15:05.470
Modified: 2026-01-09T17:15:51.300
Link: CVE-2024-27784
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD