PT-2020-6666 · Fortinet · Fortiproxy+1

Published

2020-06-16

·

Updated

2021-09-07

·

CVE-2019-17655

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.2.0 through 6.2.2 FortiOS version 6.0.9 and earlier FortiProxy version 2.0.0 FortiProxy version 1.2.9 and earlier
Description A cleartext storage vulnerability may allow an attacker to retrieve a logged-in SSL VPN user's credentials if the attacker can read the session file stored on the targeted device's system. This issue is related to the storage of confidential information in an unencrypted form. To exploit this weakness, another unrelated weakness, such as a system file leaking vulnerability, would need to be exploited first.
Recommendations For FortiOS versions 6.2.0 through 6.2.2, update to a version that fixes the cleartext storage issue. For FortiOS version 6.0.9 and earlier, update to a version that fixes the cleartext storage issue. For FortiProxy version 2.0.0, update to a version that fixes the cleartext storage issue. For FortiProxy version 1.2.9 and earlier, update to a version that fixes the cleartext storage issue. As a temporary workaround, consider restricting access to the session file stored on the targeted device's system to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03218
CVE-2019-17655

Affected Products

Fortios
Fortiproxy