9.8

CVE-2023-26204

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Data is provided by the National Vulnerability Database (NVD)
FortinetFortisiem Version >= 5.3.0 <= 5.3.3
FortinetFortisiem Version >= 6.3.0 <= 6.3.3
FortinetFortisiem Version >= 6.6.0 <= 6.6.3
FortinetFortisiem Version >= 6.7.0 <= 6.7.5
FortinetFortisiem Version5.4.0
FortinetFortisiem Version6.1.0
FortinetFortisiem Version6.1.1
FortinetFortisiem Version6.1.2
FortinetFortisiem Version6.2.0
FortinetFortisiem Version6.2.1
FortinetFortisiem Version6.4.0
FortinetFortisiem Version6.4.1
FortinetFortisiem Version6.4.2
FortinetFortisiem Version6.5.0
FortinetFortisiem Version6.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.428
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@fortinet.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-256 Plaintext Storage of a Password

Storing a password in plaintext may result in a system compromise.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.