Impact
The vulnerability allows an authenticated remote attacker to retrieve a service account password by modifying the server address in the LDAP configuration. Because the passwords are stored in a recoverable format, once authenticated the attacker can read the stored credentials. This can lead to credential compromise, enabling lateral movement or full control of the affected system.
Affected Systems
Fortinet FortiSOAR PaaS versions 7.3.x through 7.6.4 and FortiSOAR on‑premise versions 7.3.x through 7.6.4 are impacted by this issue.
Risk and Exploitability
With a CVSS score of 4.1 the vulnerability presents moderate severity. An attacker must already have authenticated remote access to the system; after authentication the attacker can alter the LDAP settings to expose passwords stored in a recoverable format. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet.
OpenCVE Enrichment