Plaintext credentials storage in DB

Summary

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.

Version Affected Solution
FortiSIEM 7.0 Not affected Not Applicable
FortiSIEM 6.7 6.7 all versions Migrate to a fixed release
FortiSIEM 6.6 6.6 all versions Migrate to a fixed release
FortiSIEM 6.5 6.5 all versions Migrate to a fixed release
FortiSIEM 6.4 6.4 all versions Migrate to a fixed release
FortiSIEM 6.3 6.3 all versions Migrate to a fixed release
FortiSIEM 6.2 6.2 all versions Migrate to a fixed release
FortiSIEM 6.1 6.1 all versions Migrate to a fixed release
FortiSIEM 5.4 5.4 all versions Migrate to a fixed release
FortiSIEM 5.3 5.3 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Martijn van Hoof from Simac IT NL B.V. for reporting this vulnerability under responsible disclosure.

Timeline

2023-06-06: Initial publication