A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-23-120 | Vendor Advisory |
https://fortiguard.com/psirt/FG-IR-23-120 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/psirt/FG-IR-23-120 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
12 Oct 2023, 19:59
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://fortiguard.com/psirt/FG-IR-23-120 - Vendor Advisory | |
First Time |
Fortinet fortios
Fortinet |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
CWE | NVD-CWE-Other |
10 Oct 2023, 17:52
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-10 17:15
Updated : 2024-11-21 08:12
NVD link : CVE-2023-37935
Mitre link : CVE-2023-37935
CVE.ORG link : CVE-2023-37935
JSON object : View
Products Affected
fortinet
- fortios
CWE