CVE-2023-36551: Infoleak
Published Sep 13, 2023
·Updated
A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.
Affected Software
1 affected component
Fortinet FortiSIEM>=6.7.0<6.7.6
Remediation
Information
Please upgrade to FortiSIEM version 7.0.0 or above Please upgrade to FortiSIEM version 6.7.6 or above Please upgrade to FortiSIEM version 6.6.0 or above
Event History
Sep 13, 2023
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the exposure of sensitive information in Fortinet FortiSIEM?
The vulnerability ID for the exposure of sensitive information in Fortinet FortiSIEM is CVE-2023-36551.
2
What is the severity of CVE-2023-36551?
CVE-2023-36551 has a severity of 5.3 (medium).
3
Which version of Fortinet FortiSIEM is affected by CVE-2023-36551?
Fortinet FortiSIEM version 6.7.0 through 6.7.5 is affected by CVE-2023-36551.
4
How can an attacker exploit CVE-2023-36551?
An attacker can exploit CVE-2023-36551 by sending a crafted HTTP request to the vulnerable Fortinet FortiSIEM software.
5
Is there a fix available for CVE-2023-36551?
Yes, a fix for CVE-2023-36551 is available. It is recommended to update Fortinet FortiSIEM to version 6.7.6 or above.