PT-2017-17919 · Fortinet · Fortios

Published

2017-12-08

·

Updated

2017-12-26

·

CVE-2017-7738

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 5.2 and below Fortinet FortiOS versions 5.4.0 through 5.4.5 Fortinet FortiOS versions 5.6.0 through 5.6.2
Description The issue allows an admin user with super admin privileges to view the current SSL VPN web portal session information, which may contain user credentials, through the fnsysctl CLI command. This could potentially lead to information disclosure.
Recommendations For Fortinet FortiOS versions 5.2 and below, update to a version above 5.2 to resolve the issue. For Fortinet FortiOS versions 5.4.0 through 5.4.5, update to a version above 5.4.5 to resolve the issue. For Fortinet FortiOS versions 5.6.0 through 5.6.2, update to a version above 5.6.2 to resolve the issue. As a temporary workaround, consider restricting access to the fnsysctl CLI command for admin users with super admin privileges until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7738

Affected Products

Fortios