QID 44065
Date Published: 2023-06-27
QID 44065: Fortinet FortiOS Sensitive Information Disclosure Vulnerability (FG-IR-22-380)
A cleartext transmission of sensitive information vulnerability CWE-319 in FortiOS and FortiProxy may allow an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.8
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
A cleartext transmission of sensitive information vulnerability CWE-319 in FortiOS and FortiProxy may allow an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-380
Vendor References
- FG-IR-22-380 -
www.fortiguard.com/psirt/FG-IR-22-380
CVEs related to QID 44065
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-380 |
|