PT-2023-6004 · Fortinet · Fortios
Published
2023-10-10
·
Updated
2023-10-12
·
CVE-2023-37935
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions 7.0.0 through 7.0.12
Fortinet FortiOS versions 7.2.0 through 7.2.5
Fortinet FortiOS version 7.4.0
Description
The issue is related to the use of the GET request method with sensitive query strings in Fortinet FortiOS, allowing an attacker to view plaintext passwords of remote services such as RDP or VNC if they can read the GET requests to those services. This can occur if the attacker has access to logs, referers, caches, etc.
Recommendations
For Fortinet FortiOS versions 7.0.0 through 7.0.12, consider disabling the use of GET requests with sensitive query strings until a patch is available.
For Fortinet FortiOS versions 7.2.0 through 7.2.5, restrict access to the FortiOS SSL VPN component to minimize the risk of exploitation.
For Fortinet FortiOS version 7.4.0, avoid using sensitive query strings in GET requests to remote services until the issue is resolved.
As a temporary workaround, consider restricting access to logs, referers, and caches that may contain sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios