CVE-2015-1457: Infoleak
Published Feb 3, 2015
·Updated
Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.
Affected Software
1 affected component
Fortinet FortiAuthenticator=3.0.0
Event History
Feb 3, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1457?
CVE-2015-1457 is considered a high severity vulnerability due to its potential to allow unauthorized file access.
2
How do I fix CVE-2015-1457?
To fix CVE-2015-1457, it is recommended to update to a version of FortiAuthenticator that is not affected by this vulnerability.
3
Who is affected by CVE-2015-1457?
CVE-2015-1457 affects local users of Fortinet FortiAuthenticator version 3.0.0.
4
What is the impact of CVE-2015-1457?
The impact of CVE-2015-1457 allows local users to read arbitrary files, leading to possible information disclosure.
5
Is there a workaround for CVE-2015-1457?
As a workaround for CVE-2015-1457, you may restrict local user access or review user permissions until a patch is available.