Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jcc-mqxf-7wr9

Опубликовано: 03 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 2.8
nvd
почти 4 года назад

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200