QID 378070
Date Published: 2023-03-23
QID 378070: Fortinet FortiManager FortiAnalyzer Information Disclosure Vulnerability (FG-IR-18-232)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager and FortiAnalyzer may allow an attacker which has obtained access to a restricted administrative account to obtain sensitive information via `diagnose debug` commands.
Affected Products:
FortiManager version 6.0.0 through 6.0.4
FortiAnalyzer version 6.0.0 through 6.0.4
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager,FortiAnalyzer
Successful exploitation of this vulnerability may lead to Information disclosure
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-18-232
Vendor References
- FG-IR-18-232 -
www.fortiguard.com/psirt/FG-IR-18-232
CVEs related to QID 378070
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-18-232 |
|