CVE-2023-22636: High severity fortinet fortiweb vulnerability
Published Feb 27, 2023
·Updated
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.
Affected Software
3 affected components
Fortinet FortiWeb>=6.3.6<=6.3.21
Fortinet FortiWeb>=6.4.0<=6.4.2
Fortinet FortiWeb>=7.0.0<=7.0.4
Remediation
Information
Please upgrade to FortiWeb version 7.0.5 or above.
Please upgrade to FortiWeb version 7.2.0 or above.
Event History
Feb 27, 2023
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-22636.
2
What is the severity of CVE-2023-22636?
The severity of CVE-2023-22636 is high.
3
How does CVE-2023-22636 affect FortiWeb?
CVE-2023-22636 affects FortiWeb versions 6.3.6 through 6.3.21, 6.4.0 through 6.4.2, and 7.0.0 through 7.0.4.
4
What can an attacker do with this vulnerability?
An attacker can access confidential configuration files by exploiting CVE-2023-22636.
5
Is there a fix available for CVE-2023-22636?
Yes, Fortinet has released a fix for CVE-2023-22636. Please refer to the Fortinet website for more information.