CVE-2024-31493
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated
Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.005
43.6th percentile
Discovered by
Third party
Vendor advisory field
Published
Jun 3, 2024
Assigned by fortinet
Description
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
Weakness: CWE-212
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSOAR
Credit
Fortinet is pleased to thank James Cato from New Zealand Police for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiSOAR version 7.3.1 or above