CVE-2023-26204: Critical severity fortinet fortisiem windows agent vulnerability
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-26204.
What is the severity level of CVE-2023-26204?
The severity level of CVE-2023-26204 is critical with a score of 9.8.
Which software versions are affected by CVE-2023-26204?
FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, and 5.3 all versions are affected by CVE-2023-26204.
How can an attacker exploit this vulnerability?
An attacker able to access user DB content can exploit this vulnerability to impersonate users and gain unauthorized access.
Is there a fix available for CVE-2023-26204?
Yes, Fortinet has released a fix for CVE-2023-26204. Please refer to the official Fortinet advisory for more information.