An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text.
References
| Link | Resource |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-455 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jun 2023, 19:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://fortiguard.com/psirt/FG-IR-22-455 - Vendor Advisory | |
| CWE | CWE-532 | |
| CPE | cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
|
| First Time |
Fortinet
Fortinet fortios Fortinet fortiproxy |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
13 Jun 2023, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-06-13 09:15
Updated : 2023-11-07 04:09
NVD link : CVE-2023-26207
Mitre link : CVE-2023-26207
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios
CWE
CWE-532
Insertion of Sensitive Information into Log File
