CVE-2024-23662: Web server ETag exposure
An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.
Other sources
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS may allow an unauthenticated attacker to fingerprint the device version via HTTP requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23662?
CVE-2024-23662 is classified as a critical vulnerability due to the exposure of sensitive information to unauthorized actors.
How do I fix CVE-2024-23662?
To fix CVE-2024-23662, upgrade FortiOS to version 7.4.2 or later, 7.2.6 or later, or apply the appropriate remediation for affected versions.
Which versions of FortiOS are affected by CVE-2024-23662?
CVE-2024-23662 affects FortiOS versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.5, 7.0.0 to 7.0.15, and 6.4.0 to 6.4.15.
What type of vulnerability is CVE-2024-23662?
CVE-2024-23662 is an information disclosure vulnerability that allows attackers to access sensitive information via HTTP requests.
Who is affected by CVE-2024-23662?
Organizations using Fortinet FortiOS versions listed in the vulnerability details are at risk of CVE-2024-23662.