CVE-2024-23107: Infoleak
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23107?
CVE-2024-23107 has been classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-23107?
To mitigate CVE-2024-23107, upgrade FortiWeb to version 7.4.1 or later, 7.2.5 or later, or 7.0.9 or later.
What types of information can be accessed through CVE-2024-23107?
CVE-2024-23107 allows an authenticated attacker to read password hashes of other administrators.
Which versions of FortiWeb are affected by CVE-2024-23107?
CVE-2024-23107 affects FortiWeb versions 6.3 all versions, 7.0.8 and below, 7.2.4 and below, and version 7.4.0.
Who is at risk with CVE-2024-23107?
Authenticated attackers with CLI access to affected versions of FortiWeb are at risk of exploiting CVE-2024-23107.