Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-36509

Опубликовано: 12 нояб. 2024
Источник: nvd
CVSS3: 4.2
CVSS3: 4.4
EPSS Низкий

Описание

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticated attacker to access the encrypted passwords of other administrators via the "Log Access Event" logs page.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Версия от 6.3.0 (включая) до 7.4.4 (исключая)
cpe:2.3:a:fortinet:fortiweb:7.6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00048
Низкий

4.2 Medium

CVSS3

4.4 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 4.2
github
около 1 года назад

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticated attacker to access the encrypted passwords of other administrators via the "Log Access Event" logs page.

EPSS

Процентиль: 15%
0.00048
Низкий

4.2 Medium

CVSS3

4.4 Medium

CVSS3

Дефекты

CWE-497