Information Disclosure Vulnerability in Fortinet FortiSIEM Product
CVE-2023-36551

4.2MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
13 September 2023

Summary

An information exposure vulnerability exists in Fortinet's FortiSIEM product versions 6.7.0 to 6.7.5, which could allow unauthorized access to sensitive information. This issue arises when the product improperly handles crafted HTTP requests, leading to the potential disclosure of confidential data. Organizations using vulnerable versions are urged to assess and mitigate this risk to protect their sensitive information.

Affected Version(s)

FortiSIEM 6.7.0 <= 6.7.5

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.