CVE-2023-45585: Fortinet Fortisiem
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.
Affected products
- Fortinet Fortisiem: from 5.3.0, up to and including 5.3.3; from 6.7.0, up to and including 6.7.6; version 5.4.0 only; version 6.1.0 only; version 6.1.1 only; version 6.1.2 only; …
Published 2023-11-14. Last modified 2026-06-17.