CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-40720
Severity
HIGH
CVSS
7.1
EPSS
0.85%
Original NVD Description
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
Related CVEs
Other vulnerabilities affecting the same vendor(s)