First published: Wed Dec 13 2017(Updated: )
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | <=5.2 | |
Fortinet FortiOS IPS Engine | >=5.4.0<=5.4.5 | |
Fortinet FortiOS IPS Engine | >=5.6.0<=5.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7738 is considered to be a medium severity vulnerability.
CVE-2017-7738 affects users of Fortinet FortiOS versions 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, and 5.2 and below.
To fix CVE-2017-7738, upgrade Fortinet FortiOS to the latest version that addresses this vulnerability.
CVE-2017-7738 is classified as an Information Disclosure vulnerability.
No, only an admin user with super_admin privileges can exploit CVE-2017-7738.