QID 43920
Date Published: 2022-10-17
QID 43920: FortiOS Information Disclosure Vulnerability (FG-IR-21-074)
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Affected Products:
FortiOS version 7.0.1 and below
FortiOS version 6.4.6 and below
FortiOS version 6.2.9 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable version of FortiOS may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-074
Vendor References
- FG-IR-21-074 -
www.fortiguard.com/psirt/FG-IR-21-074
CVEs related to QID 43920
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-074 |
|