Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-41327: Fortiguard

A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.

CVE
#vulnerability#ios#auth

** PSIRT Advisories**

FortiOS/FortiProxy - Read Only administrator can intercept sensitive data

Summary

A cleartext transmission of sensitive information vulnerability [CWE-319] in FortiOS & FortiProxy may allow an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.

Affected Products

FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.8
FortiProxy version 7.2.0 through 7.2.1
FortiProxy version 7.0.0 through 7.0.7

Solutions

Please upgrade to FortiOS version 7.2.5 or above
Please upgrade to FortiOS version 7.0.9 or above
Please upgrade to FortiProxy version 7.2.2 or above
Please upgrade to FortiProxy version 7.0.8 or above

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2023-06-09: Initial publication

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda