PT-2018-2863 · Fortinet · Fortios
Published
2018-11-22
·
Updated
2019-10-03
·
CVE-2018-13376
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions 5.2 through 5.6.3
Fortinet FortiOS versions 5.4.6 through 5.4.7
Description
The issue is related to an uninitialized memory buffer leak in the web proxy's disclaimer response web pages. This could potentially cause sensitive data to be displayed in the HTTP response. The vulnerability is associated with resource management errors, which could allow a remote attacker to disclose protected information.
Recommendations
For Fortinet FortiOS versions 5.2 through 5.6.3, consider disabling the web proxy's disclaimer response web pages until a patch is available.
For Fortinet FortiOS versions 5.4.6 through 5.4.7, restrict access to the web proxy to minimize the risk of exploitation.
As a temporary workaround, avoid using the web proxy's disclaimer response web pages in Fortinet FortiOS until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios