CVE-2024-23104: Infoleak
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only permission on system maintenance to access backup information via crafted HTTP requests
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23104?
CVE-2024-23104 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-23104?
To fix CVE-2024-23104, users should upgrade to the latest patched version of Fortinet FortiNDR or FortiVoice software as recommended by the vendor.
What systems are affected by CVE-2024-23104?
CVE-2024-23104 affects Fortinet FortiNDR versions 7.6.0, 7.4.0 through 7.4.8, and all versions of FortiNDR 7.2, 7.1, 7.0, as well as FortiVoice versions 7.0.0 through 7.0.1.
Who can exploit CVE-2024-23104?
CVE-2024-23104 can be exploited by a remote authenticated attacker with access to the affected systems.
What type of vulnerability is CVE-2024-23104?
CVE-2024-23104 is categorized as an exposure of sensitive information to an unauthorized actor vulnerability.