PT-2019-2823 · Fortinet · Fortimanager
Publicado
2019-04-23
·
Atualizado
2019-10-03
·
CVE-2018-1360
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiManager versions 5.2.0 through 5.2.7
FortiManager versions 5.4.0 and 5.4.1
Description
The issue is related to the lack of protection for service data in Fortinet FortiManager. It may allow a remote attacker to obtain the administrator password by intercepting REST API JSON responses. This could be done by an unauthenticated attacker in a man-in-the-middle position.
Recommendations
For FortiManager versions 5.2.0 through 5.2.7, update to a version that includes the necessary security fixes to prevent cleartext transmission of sensitive information.
For FortiManager versions 5.4.0 and 5.4.1, apply the recommended configuration changes to secure the REST API JSON responses and prevent unauthorized access to sensitive data.
As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.
Correção
Cleartext Transmission of Sensitive Information
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Fortimanager