QID 44091
Date Published: 2023-07-14
QID 44091: FortiOS - Multiple Pre-Authentication Information Disclosure Vulnerabilities (FG-IR-19-043)
Multiple information exposure vulnerabilities in FortiOS may allow an unauthenticated attacker to perform some information gathering via parsing the HTTP headers, web portal certificate, and error messages. The exposed information includes the FortiGate's model, serial number and internal IP address.
Affected Versions:
FortiOS 6.0.x all versions before 6.0.4
FortiOS 6.2.x all versions before 6.2.3
FortiOS 5.6.x all versions before 5.6.6
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID also contains banner based detection .
Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform some information gathering via parsing the HTTP headers, web portal certificate, and error messages. The exposed information includes the FortiGate's model, serial number and internal IP address.
- FG-IR-19-043 -
www.fortiguard.com/psirt/FG-IR-19-043
CVEs related to QID 44091
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-043 |
|