Описание
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
3.3 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
Связанные уязвимости
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
Уязвимость программного средства для централизованного управления устройствами Fortinet FortiManager, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
3.3 Low
CVSS3
4.3 Medium
CVSS3