Impact
The vulnerability arises from the inclusion of sensitive information in the source code of FortiMonitorOnSight. This exposure can lead to unauthorized access or privilege escalation as an attacker might leverage leaked credentials or configuration data. The weakness aligns with CWE-540, indicating sensitive data stored in source code.
Affected Systems
Affected products are Fortinet FortiMonitorOnSight versions 7.2.0 through 7.2.7, encompassing releases 7.2.0–7.2.2 and 7.2.4–7.2.7. All these versions lack the fix which removes the sensitive information from the source.
Risk and Exploitability
The CVSS score is 9.6, signifying a high severity with potential for significant impact. An EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack vector is not explicitly provided; however, the description suggests that an attacker could gain improper access control by exploiting source code exposure. Given the severity, the risk to systems is considerable if the source code or configuration is exposed.
OpenCVE Enrichment