An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
2024-05-14T17:15:19.067
2024-11-21T08:20:01.767
Modified
CVSSv3.1: 7.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortivoice | ≤ 6.0.12 | Yes |
Application | fortinet | fortivoice | ≤ 6.4.8 | Yes |
Application | fortinet | fortivoice | 7.0.0 | Yes |
Application | fortinet | fortivoice | 7.0.1 | Yes |