QID 44053
Date Published: 2023-05-31
QID 44053: FortiOS Secure Sockets Layer (SSL) Virtual Private Network (VPN) Information Disclosure Vulnerability (FG-IR-19-217) (Unauthenticated Check)
A cleartext storage in a file or on disk vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a logged-in SSL VPN user's credentials.
Affected Products:
FortiOS 6.2.0 to 6.2.2, 6.0.9 and below
QID Detection Logic (No Auth) :
Detection checks for vulnerable version of FortiOS.
To successfully exploit this weakness, another unrelated weakness (eg: a system file leaking vulnerability) would therefore need to be exploited first.
Solution
Vendor has released fix to address these vulnerabilities. Upgrade to FortiOS versions 6.0.10 or 6.2.3 or above
Refer to FG-IR-19-217 for further details.
Vendor References
- FG-IR-19-217 -
fortiguard.com/psirt/FG-IR-19-217
CVEs related to QID 44053
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-217 |
|