Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortivoice  >> 6.0.12  Security Vulnerabilities
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
CVSS Score
7.1
EPSS Score
0.0
Published
2024-05-14
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
CVSS Score
6.5
EPSS Score
0.005
Published
2024-01-10


Contact Us

Shodan ® - All rights reserved