CVE-2023-40720

7.1HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP config

公開日: 5/14/2024更新日: 11/21/2024

説明

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.

AI分析AIによる分析

影響を受ける製品

fortinetfortivoice
fortinetfortivoice
fortinetfortivoice
7.0.0
fortinetfortivoice
7.0.1

参照