QID 44048
Date Published: 2023-05-31
QID 44048: FortiOS Inter-Virtual domains (VDOM) Information Leakage Vulnerability (FG-IR-22-036) (Unauthenticated Check)
An improper access control vulnerability [CWE-284] in FortiOS may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.
Affected Products:
FortiOS version 7.0.0 through 7.0.5
FortiOS version 6.4.0 through 6.4.8
FortiOS version 6.2.0 through 6.2.11
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-036
Vendor References
- FG-IR-22-036 -
www.fortiguard.com/psirt/FG-IR-22-036
CVEs related to QID 44048
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-036 |
|