PT-2018-2863 · Fortinet · Fortios

Published

2018-11-22

·

Updated

2019-10-03

·

CVE-2018-13376

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 5.2 through 5.6.3 Fortinet FortiOS versions 5.4.6 through 5.4.7
Description The issue is related to an uninitialized memory buffer leak in the web proxy's disclaimer response web pages. This could potentially cause sensitive data to be displayed in the HTTP response. The vulnerability is associated with resource management errors, which could allow a remote attacker to disclose protected information.
Recommendations For Fortinet FortiOS versions 5.2 through 5.6.3, consider disabling the web proxy's disclaimer response web pages until a patch is available. For Fortinet FortiOS versions 5.4.6 through 5.4.7, restrict access to the web proxy to minimize the risk of exploitation. As a temporary workaround, avoid using the web proxy's disclaimer response web pages in Fortinet FortiOS until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02389
CVE-2018-13376

Affected Products

Fortios