Aller au contenu

Fiche vulnérabilité

CVE-2023-40720 : faille élevée fortinet fortivoice (CVSS 7.1)

Description

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.

En bref

Sévérité
Élevée (CVSS 7.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Exploitation active
Non signalée par la CISA
Publication
14 mai 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • fortinet fortivoice

Références

Rechercher une autre vulnérabilité dans la base CVE