CVE-2023-26207: SMTP password ciphertext exposure in Log
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS / FortiProxy log events may allow a remote authenticated attacker to read certain passwords in ciphertext.
Other sources
An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-26207?
CVE-2023-26207 is an insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10.
How does CVE-2023-26207 affect Fortinet FortiOS?
CVE-2023-26207 allows an attacker to read certain passwords in plain text on Fortinet FortiOS 7.2.0 through 7.2.4.
How does CVE-2023-26207 affect Fortinet FortiProxy?
CVE-2023-26207 allows an attacker to read certain passwords in plain text on Fortinet FortiProxy 7.0.0 through 7.0.10.
What is the severity of CVE-2023-26207?
The severity of CVE-2023-26207 is medium with a CVSS score of 6.5.
Is there a fix for CVE-2023-26207?
There is no fix available for CVE-2023-26207 at the moment. Please refer to the vendor's security advisory for updates.