Required CVE Record Information
Description
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.2 | MEDIUM | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:X/RC:C |
References 1 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.