First published: Wed May 29 2019(Updated: )
An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | <=5.6.5 | |
FortiOS | >=5.6.6<=6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13365 has a medium severity rating due to potential information exposure.
To fix CVE-2018-13365, upgrade FortiOS to a version that is higher than 6.0.1 or 5.6.5.
CVE-2018-13365 allows attackers to learn private IP addresses and hostnames of FortiGate devices.
FortiOS versions 6.0.1, 5.6.5, and earlier versions are affected by CVE-2018-13365.
Attackers can exploit CVE-2018-13365 by accessing the Application Control Block page to retrieve sensitive information.