First published: Tue Jan 07 2020(Updated: )
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSIEM | <5.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-6700.
The severity of CVE-2019-6700 is medium with a severity value of 6.5.
CVE-2019-6700 is an information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier that may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.
CVE-2019-6700 affects FortiSIEM 5.2.2 and earlier versions.
Yes, a fix is available for CVE-2019-6700. It is recommended to update to FortiSIEM version 5.2.5 or later.