First published: Tue Jul 09 2024(Updated: )
Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] in FortiAIOps version 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAIOps | =2.0.0 |
Please upgrade to FortiAIOps version 2.0.1 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27784 has been assessed as a high severity vulnerability due to its potential for sensitive information exposure.
CVE-2024-27784 affects users of FortiAIOps version 2.0.0.
To fix CVE-2024-27784, upgrade FortiAIOps to a patched version provided by Fortinet.
CVE-2024-27784 is classified as an information exposure vulnerability, specifically allowing unauthorized access to sensitive data.
Yes, CVE-2024-27784 can be exploited by an authenticated, remote attacker.