CVE-2016-4968: Infoleak
Published Sep 21, 2016
·Updated
The linkreport/tmp/adminglobal page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request.
Affected Software
1 affected component
Fortinet FortiWan<=4.2.4
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4968?
CVE-2016-4968 is classified as a medium severity vulnerability due to its potential for allowing remote authenticated users to access sensitive administrator cookies.
2
How do I fix CVE-2016-4968?
To fix CVE-2016-4968, upgrade Fortinet FortiWan to version 4.2.5 or later.
3
Who is affected by CVE-2016-4968?
CVE-2016-4968 affects users of Fortinet FortiWan software versions prior to 4.2.5.
4
What type of attack can be performed using CVE-2016-4968?
An attacker can leverage CVE-2016-4968 to perform a session hijacking attack by obtaining administrator cookies.
5
Is CVE-2016-4968 a local or remote vulnerability?
CVE-2016-4968 is a remote vulnerability that requires authentication to exploit.