PT-2021-7468 · Fortinet · Fortiweb
Published
2021-04-06
·
Updated
2021-04-20
·
CVE-2020-15942
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiWeb versions 6.2.x through 6.2.3
FortiWeb versions 6.3.x through 6.3.4
Description
An information disclosure issue in the Web Vulnerability Scan profile of Fortinet's FortiWeb may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile. This is related to insufficient protection of credentials.
Recommendations
For FortiWeb versions 6.2.x through 6.2.3, update to version 6.2.4 or later.
For FortiWeb versions 6.3.x through 6.3.4, update to version 6.3.5 or later.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiweb