CVE-2023-40720

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-23-282 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:7.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-05-14 17:15

Updated : 2024-05-23 16:38


NVD link : CVE-2023-40720

Mitre link : CVE-2023-40720

CVE.ORG link : CVE-2023-40720


JSON object : View

Products Affected

fortinet

  • fortivoice
CWE
CWE-639

Authorization Bypass Through User-Controlled Key