QID 43995
Date Published: 2023-03-23
QID 43995: FortiOS Information Disclosure Vulnerability (FG-IR-22-364)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS and FortiProxy administrative interface may allow an unauthenticated attacker to obtain sensitive logging information on the device via crafted HTTP GET requests.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS version 6.2.3 and above
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable OS may allow an unauthenticated attacker to obtain sensitive logging information on the device via crafted HTTP GET requests.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-364
Vendor References
- FG-IR-22-364 -
www.fortiguard.com/psirt/FG-IR-22-364
CVEs related to QID 43995
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-364 |
|