#VU75015 Unprotected Transport of Credentials in FortiAnalyzer - CVE-2023-23776
Published: April 12, 2023
FortiAnalyzer
Fortinet, Inc
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to the log-fetch client request password is displayed in clear text in the heartbeat response. A remote user can obtain the client machine password in plain text in a heartbeat response when a log-fetch request is made from the FortiAnalyzer.