CVE-2023-40715: Medium severity fortinet fortitester vulnerability
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40715.
What is the title of this vulnerability?
The title of this vulnerability is 'A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3.'
What is the severity of CVE-2023-40715?
The severity of CVE-2023-40715 is medium, with a severity value of 5.5.
What is the impact of this vulnerability?
This vulnerability may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update FortiTester to a version that is above 7.2.3.