Plaintext Password Storage Vulnerability in FortiSIEM by Fortinet
CVE-2023-26204
3.6LOW
What is CVE-2023-26204?
A vulnerability in FortiSIEM allows for plaintext storage of passwords, enabling an attacker with access to the user database to impersonate any administrator user through the device's graphical user interface. This flaw affects all versions from 5.3 up to 6.7, posing a significant risk of unauthorized access to critical administrative functions.
Affected Version(s)
FortiSIEM 6.7.0 <= 6.7.5
FortiSIEM 6.6.0 <= 6.6.3
FortiSIEM 6.5.0 <= 6.5.1