Windows agent password is visible in the logs

Summary

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

Affected Products

FortiSIEM 7.1 all versions are not affected
FortiSIEM version 7.0.0
FortiSIEM version 6.7.0 through 6.7.5
FortiSIEM 6.6 all versions are not affected
FortiSIEM 6.5 all versions are not affected
FortiSIEM 6.4 all versions are not affected
FortiSIEM 6.3 all versions are not affected
FortiSIEM 6.2 all versions are not affected
FortiSIEM 6.1 all versions are not affected
FortiSIEM 5.4 all versions are not affected
FortiSIEM 5.3 all versions are not affected

Solutions

Please upgrade to FortiSIEM version 7.1.0 or above
Please upgrade to FortiSIEM version 7.0.1 or above
Please upgrade to FortiSIEM version 6.7.6 or above

Acknowledgement

Internally discovered and reported by Darren Hart from FortiSIEMCloud development team.

Timeline

2023-11-13: Initial publication