QID 44106
Date Published: 2023-10-23
QID 44106: FortiOS Information Disclosure Vulnerability (FG-IR-23-120)
A use of GET request method with sensitive query strings vulnerability [CWE-598] in the FortiOS SSL VPN component may allow an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services (found in logs, referers, caches, etc...)
Affected Versions:
FortiOS version 7.4.0
FortiOS version 7.2.0 through 7.2.5
FortiOS version 7.0.0 through 7.0.12
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allow an authenticated attacker to view plaintext passwords of remote services such as RDP or VNC.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-120
- FG-IR-23-120 -
www.fortiguard.com/psirt/FG-IR-23-120
CVEs related to QID 44106
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-120 |
|