PT-2017-17915 · Fortinet · Fortiportal

Published

2017-05-26

·

Updated

2017-05-31

·

CVE-2017-7731

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiPortal versions 4.0.0 and below
Description A weak password recovery issue allows attackers to carry out information disclosure via the Forgotten Password feature.
Recommendations For Fortinet FortiPortal versions 4.0.0 and below, update to a version above 4.0.0 to resolve the issue. As a temporary workaround, consider disabling the Forgotten Password feature until a patch is available. Restrict access to the Forgotten Password feature to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7731

Affected Products

Fortiportal