Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-40720


An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.


Published

2024-05-14T17:15:19.067

Last Modified

2024-11-21T08:20:01.767

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortivoice ≤ 6.0.12 Yes
Application fortinet fortivoice ≤ 6.4.8 Yes
Application fortinet fortivoice 7.0.0 Yes
Application fortinet fortivoice 7.0.1 Yes

References