QID 43941
Date Published: 2022-12-02
QID 43941: FortiOS - Exposure of Sensitive Information to an Unauthorized actor Vulnerability via SNI Client Hello TLS packets (FG-IR-20-091)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS may allow a privileged attacker to disclose sensitive information via SNI Client Hello TLS packets.
Affected Products
All FortiOS versions are impacted by this vulnerability.
Vulnerable versions allow a privileged attacker to disclose sensitive information via SNI Client Hello TLS packets.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-20-091
Vendor References
- FG-IR-20-091 -
www.fortiguard.com/psirt/FG-IR-20-091
CVEs related to QID 43941
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-091 |
|