QID 43943
Date Published: 2022-12-15
QID 43943: FortiOS - Telnet on the SSL-Virtual Private Network (VPN) Interface results in Information Leak Vulnerability (FG-IR-22-223)
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.
Affected Products:
FortiOS version 7.2.0
FortiOS version 7.0.0 through 7.0.6
FortiOS version 6.4.0 through 6.4.9
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiOS.
Vulnerable version may allow a remote unauthenticated attacker to agin information about LDAP and SAML settings configured in FortiOS.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-223
Vendor References
- FG-IR-22-223 -
www.fortiguard.com/psirt/FG-IR-22-223
CVEs related to QID 43943
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-223 |
|