PT-2023-7380 · Fortinet · Fortianalyzer+1

CVE-2023-40719

·

Publicado

2023-11-14

·

Atualizado

2023-11-21

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiAnalyzer and FortiManager versions 7.0.0 through 7.0.8 Fortinet FortiAnalyzer and FortiManager versions 7.2.0 through 7.2.3 Fortinet FortiAnalyzer and FortiManager version 7.4.0
Description A use of hard-coded credentials issue allows an attacker to access private testing data via the use of static credentials. This issue is related to the use of static credentials in the software, which can be exploited by an attacker to gain access to confidential information.
Recommendations For Fortinet FortiAnalyzer and FortiManager versions 7.0.0 through 7.0.8, update to a version that does not use hard-coded credentials. For Fortinet FortiAnalyzer and FortiManager versions 7.2.0 through 7.2.3, update to a version that does not use hard-coded credentials. For Fortinet FortiAnalyzer and FortiManager version 7.4.0, update to a version that does not use hard-coded credentials. As a temporary workaround, consider restricting access to the affected systems until a patch is available.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08412
CVE-2023-40719

Produtos afetados

Fortianalyzer
Fortimanager