Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcfc-fhv2-9grh

Опубликовано: 02 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.

EPSS

Процентиль: 65%
0.0049
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
больше 3 лет назад

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость SSL-VPN-портала операционных систем FortiOS, позволяющая нарушителю получить информацию о настройках LDAP и SAML

EPSS

Процентиль: 65%
0.0049
Низкий

7.5 High

CVSS3