QID 378070

Date Published: 2023-03-23

QID 378070: Fortinet FortiManager FortiAnalyzer Information Disclosure Vulnerability (FG-IR-18-232)

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager and FortiAnalyzer may allow an attacker which has obtained access to a restricted administrative account to obtain sensitive information via `diagnose debug` commands.

Affected Products:
FortiManager version 6.0.0 through 6.0.4
FortiAnalyzer version 6.0.0 through 6.0.4

QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager,FortiAnalyzer

Successful exploitation of this vulnerability may lead to Information disclosure

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-18-232

    Vendor References

    CVEs related to QID 378070

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-18-232 URL Logo www.fortiguard.com/psirt/FG-IR-18-232