Information Disclosure Vulnerability in Fortinet FortiSIEM Product
CVE-2023-36551
4.2MEDIUM
Summary
An information exposure vulnerability exists in Fortinet's FortiSIEM product versions 6.7.0 to 6.7.5, which could allow unauthorized access to sensitive information. This issue arises when the product improperly handles crafted HTTP requests, leading to the potential disclosure of confidential data. Organizations using vulnerable versions are urged to assess and mitigate this risk to protect their sensitive information.
Affected Version(s)
FortiSIEM 6.7.0 <= 6.7.5
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved