---
cve: "CVE-2023-26204"
severity: "LOW"
cvss: 3.6
epss: "44%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2023-06-13 09:15:16"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T21:31:15+02:00"
---

# CVE-2023-26204

> 3.6 LOW

## Beschreibung

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:U/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-256** — Plaintext Storage of a Password
  The product stores a password in plaintext within resources such as memory or files.

## Referenzen

- <https://fortiguard.com/psirt/FG-IR-21-141>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-26204) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
