CVE-2023-22636

6.6MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
27 February 2023

Summary

An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.

Affected Version(s)

FortiWeb 7.0.0 <= 7.0.4

FortiWeb 6.4.0 <= 6.4.2

FortiWeb 6.3.6 <= 6.3.21

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.