PT-2019-2823 · Fortinet · Fortimanager

Publicado

2019-04-23

·

Atualizado

2019-10-03

·

CVE-2018-1360

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiManager versions 5.2.0 through 5.2.7 FortiManager versions 5.4.0 and 5.4.1
Description The issue is related to the lack of protection for service data in Fortinet FortiManager. It may allow a remote attacker to obtain the administrator password by intercepting REST API JSON responses. This could be done by an unauthenticated attacker in a man-in-the-middle position.
Recommendations For FortiManager versions 5.2.0 through 5.2.7, update to a version that includes the necessary security fixes to prevent cleartext transmission of sensitive information. For FortiManager versions 5.4.0 and 5.4.1, apply the recommended configuration changes to secure the REST API JSON responses and prevent unauthorized access to sensitive data. As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.

Correção

Cleartext Transmission of Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02781
CVE-2018-1360

Produtos afetados

Fortimanager