QID 44045
Date Published: 2023-05-31
QID 44045: FortiOS - Telnet on the SSL-Virtual Private Network (VPN) Interface results in Information Leak Vulnerability (FG-IR-22-223) (Unauthenticated Check)
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.
Affected Products:
FortiOS version 7.2.0
FortiOS version 7.0.0 through 7.0.6
FortiOS version 6.4.0 through 6.4.9
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable versions of FortiOS.
Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP or HTTPS GET requests.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-363
Vendor References
- FG-IR-22-223 -
www.fortiguard.com/psirt/FG-IR-22-223
CVEs related to QID 44045
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-363 |
|