QID 43904

Date Published: 2022-10-17

QID 43904: FortiOS Inter-Virtual domains (VDOM) Information Leakage Vulnerability (FG-IR-22-036)

An improper access control vulnerability [CWE-284] in FortiOS may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.

Affected Products:
FortiOS version 7.0.0 through 7.0.5
FortiOS version 6.4.0 through 6.4.8
FortiOS version 6.2.0 through 6.2.11

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-22-036

    Vendor References

    CVEs related to QID 43904

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-036 URL Logo www.fortiguard.com/psirt/FG-IR-22-036