Описание
A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
EPSS
4.2 Medium
CVSS3
4.4 Medium
CVSS3
Дефекты
Связанные уязвимости
A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.
Уязвимость интерфейса командной строки (CLI) системы управления учетными данными FortiPAM, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
4.2 Medium
CVSS3
4.4 Medium
CVSS3