QID 44182
Date Published: 2024-04-11
QID 44182: FortiOS Web server ETag Exposure Vulnerability (FG-IR-23-224)
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS may allow an unauthenticated attacker to fingerprint the device version via HTTP requests.
Affected Versions:
FortiOS 7.4 versions 7.4.0 through 7.4.1
FortiOS 7.2 versions 7.2.0 through 7.2.5
FortiOS 7.0 all versions
FortiOS 6.4 all versions
QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS may allow an unauthenticated attacker to fingerprint the device version via HTTP requests.
Solution
The vendor advised to refer to advisory FG-IR-23-224.
Vendor References
- FG-IR-23-224 -
fortiguard.fortinet.com/psirt/FG-IR-23-224
CVEs related to QID 44182
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-224 |
|