PT-2019-2823 · Fortinet · Fortimanager

Published

2019-04-23

·

Updated

2019-10-03

·

CVE-2018-1360

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiManager versions 5.2.0 through 5.2.7 FortiManager versions 5.4.0 and 5.4.1
Description The issue is related to the lack of protection for service data in Fortinet FortiManager. It may allow a remote attacker to obtain the administrator password by intercepting REST API JSON responses. This could be done by an unauthenticated attacker in a man-in-the-middle position.
Recommendations For FortiManager versions 5.2.0 through 5.2.7, update to a version that includes the necessary security fixes to prevent cleartext transmission of sensitive information. For FortiManager versions 5.4.0 and 5.4.1, apply the recommended configuration changes to secure the REST API JSON responses and prevent unauthorized access to sensitive data. As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02781
CVE-2018-1360

Affected Products

Fortimanager