CVE-2024-36509: Medium severity fortinet fortiweb vulnerability
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticated attacker to access the encrypted passwords of other administrators via the "Log Access Event" logs page.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36509?
CVE-2024-36509 has a medium severity rating due to the risk of unauthorized access to sensitive system information.
How do I fix CVE-2024-36509?
To fix CVE-2024-36509, upgrade FortiWeb to version 7.4.4 or later, or to other secure versions as specified in the advisory.
Which versions of FortiWeb are affected by CVE-2024-36509?
CVE-2024-36509 affects FortiWeb versions 7.6.0, 7.4.3 and below, 7.2.10 and below, 7.0.10 and below, and 6.3.23 and below.
What type of information is exposed in CVE-2024-36509?
CVE-2024-36509 exposes encrypted passwords and sensitive system information to authenticated attackers.
Is authentication required to exploit CVE-2024-36509?
Yes, an authenticated attacker can exploit CVE-2024-36509 to access sensitive information.