Information Exposure Vulnerability in Fortinet FortiNDR and FortiVoice Products
CVE-2024-23104
5.4MEDIUM
What is CVE-2024-23104?
An exposure of sensitive information vulnerability exists in Fortinet’s FortiNDR and FortiVoice products, allowing remote authenticated attackers with read-only system maintenance permissions to access sensitive backup information. This can be exploited via specially crafted HTTP requests, potentially compromising user privacy and system security.
Affected Version(s)
FortiNDR 7.6.0
FortiNDR 7.4.0 <= 7.4.8
FortiNDR 7.2.0 <= 7.2.5