Lucene search

K
cveFortinetCVE-2017-7738
HistoryDec 13, 2017 - 10:29 p.m.

CVE-2017-7738

2017-12-1322:29:00
CWE-200
fortinet
web.nvd.nist.gov
28
information security
vulnerability
fortinet
fortios
admin privileges
ssl vpn
web portal
user credentials
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

32.2%

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.

Affected configurations

Nvd
Node
fortinetfortiosRange5.2
OR
fortinetfortiosRange5.4.05.4.5
OR
fortinetfortiosRange5.6.05.6.2
VendorProductVersionCPE
fortinetfortios*cpe:2.3:a:fortinet:fortios:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "FortiOS",
    "vendor": "Fortinet, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "5.6.0 to 5.6.2"
      },
      {
        "status": "affected",
        "version": "5.4.0 to 5.4.5"
      },
      {
        "status": "affected",
        "version": "5.2 and below"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

32.2%

Related for CVE-2017-7738