PT-2019-2823 · Fortinet · Fortimanager
Published
2019-04-23
·
Updated
2019-10-03
·
CVE-2018-1360
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiManager versions 5.2.0 through 5.2.7
FortiManager versions 5.4.0 and 5.4.1
Description
The issue is related to the lack of protection for service data in Fortinet FortiManager. It may allow a remote attacker to obtain the administrator password by intercepting REST API JSON responses. This could be done by an unauthenticated attacker in a man-in-the-middle position.
Recommendations
For FortiManager versions 5.2.0 through 5.2.7, update to a version that includes the necessary security fixes to prevent cleartext transmission of sensitive information.
For FortiManager versions 5.4.0 and 5.4.1, apply the recommended configuration changes to secure the REST API JSON responses and prevent unauthorized access to sensitive data.
As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortimanager