Vulnerability Description
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortisiem | >= 5.3.0, <= 5.3.3 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-23-392Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-23-392Vendor Advisory
FAQ
What is CVE-2023-45585?
CVE-2023-45585 is a vulnerability with a CVSS score of 2.3 (LOW). An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and be...
How severe is CVE-2023-45585?
CVE-2023-45585 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45585?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortisiem.