VYPR
Medium severity5.5NVD Advisory· Published Jun 3, 2024· Updated Jun 17, 2026

CVE-2024-23107

CVE-2024-23107

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Fortinet/Fortiweb4 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.0,<=6.3.23
    • cpe:2.3:a:fortinet:fortiweb:7.4.0:*:*:*:*:*:*:*
    • (no CPE)range: 7.4.0, 7.2.4 and below, 7.0.8 and below, 6.3 all versions
    • (no CPE)range: 7.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.