Impact
The vulnerability allows an authenticated remote attacker to retrieve a service account password by modifying the server address in the LDAP configuration. Passwords are stored in a recoverable format, enabling the attacker to read the stored credentials once authenticated. This can lead to credential compromise and potential lateral movement or full control of the affected system.
Affected Systems
Fortinet FortiSOAR PaaS versions 7.3.x through 7.6.4 and FortiSOAR on‑premise versions 7.3.x through 7.6.4 are impacted by this issue.
Risk and Exploitability
With a CVSS score of 4.1, the vulnerability presents moderate severity. Availability of exploitation depends on the attacker having prior authenticated remote access to the system. Once authenticated, the attacker can alter LDAP settings to access passwords that are stored in a recoverable format. The EPSS score is not available and the vulnerability is not listed in KEV, indicating no known widespread exploitation yet.
OpenCVE Enrichment