Cleartext storage of sensitive information in FortiSIEM - CVE-2018-13378
Published: January 8, 2020
FortiSIEM
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to admin portal of FortiSIEM stores the LDAP password for authentication in clear text in HTML source code. A remote authenticated attacker can obtain the password and use it to perform further attacks against network infrastructure.