PT-2023-1860 · Fortinet · Fortiproxy+1

CVE-2022-41329

·

Publicado

2023-03-07

·

Atualizado

2023-03-14

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiProxy versions 7.0.0 through 7.0.7 FortiProxy versions 7.2.0 through 7.2.1 FortiOS versions 7.0.0 through 7.0.9 FortiOS versions 7.2.0 through 7.2.3
Description The issue is related to insufficient protection of internal data in the administrative interface of FortiOS and FortiProxy, allowing an unauthenticated attacker to obtain sensitive logging information on the device via crafted HTTP GET requests.
Recommendations For FortiProxy versions 7.0.0 through 7.0.7, update to a version outside of this range to mitigate the risk. For FortiProxy versions 7.2.0 through 7.2.1, update to a version outside of this range to mitigate the risk. For FortiOS versions 7.0.0 through 7.0.9, update to a version outside of this range to mitigate the risk. For FortiOS versions 7.2.0 through 7.2.3, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the administrative interface until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01459
CVE-2022-41329

Produtos afetados

Fortios
Fortiproxy