PT-2017-17919 · Fortinet · Fortios
Published
2017-12-08
·
Updated
2017-12-26
·
CVE-2017-7738
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions 5.2 and below
Fortinet FortiOS versions 5.4.0 through 5.4.5
Fortinet FortiOS versions 5.6.0 through 5.6.2
Description
The issue allows an admin user with super admin privileges to view the current SSL VPN web portal session information, which may contain user credentials, through the
fnsysctl CLI command. This could potentially lead to information disclosure.Recommendations
For Fortinet FortiOS versions 5.2 and below, update to a version above 5.2 to resolve the issue.
For Fortinet FortiOS versions 5.4.0 through 5.4.5, update to a version above 5.4.5 to resolve the issue.
For Fortinet FortiOS versions 5.6.0 through 5.6.2, update to a version above 5.6.2 to resolve the issue.
As a temporary workaround, consider restricting access to the
fnsysctl CLI command for admin users with super admin privileges until a patch is available.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios