Lucene search

K
fortinetFortiGuard LabsFG-IR-19-217
HistorySep 07, 2021 - 12:00 a.m.

Protect

2021-09-0700:00:00
FortiGuard Labs
www.fortiguard.com
16
cleartext storage
fortios
ssl vpn
vulnerability
attacker
user credentials

EPSS

0.002

Percentile

55.1%

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a logged-in SSL VPN user’s credentials should that attacker be able to read the session file stored on the targeted device’s system.

EPSS

0.002

Percentile

55.1%