First published: Tue Apr 09 2019(Updated: )
An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | <=5.6.7 | |
Fortinet FortiOS | =6.0.0 | |
Fortinet FortiOS | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13366 is classified as a medium severity information disclosure vulnerability.
To mitigate CVE-2018-13366, upgrade Fortinet FortiOS to version 6.0.2 or above, or 5.6.8 or above.
CVE-2018-13366 allows an attacker to disclose the serial number of FortiGate devices through the hostname field in PPTP protocol packets.
FortiOS versions 6.0.1, 6.0.0, and 5.6.7 and below are affected by CVE-2018-13366.
Yes, CVE-2018-13366 directly impacts the security of FortiGate devices by revealing sensitive information.