CVE-2018-13367: Infoleak
Published Aug 23, 2019
·Updated
An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as version, models, via parsing a JavaScript file through admin webUI.
Affected Software
1 affected component
Fortinet FortiOS<=6.2.0
Event History
Aug 23, 2019
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-13367?
CVE-2018-13367 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-13367?
To fix CVE-2018-13367, upgrade to FortiOS version 6.2.4 or later.
3
What types of information can be exposed due to CVE-2018-13367?
CVE-2018-13367 may allow the exposure of platform information such as version and model.
4
Is CVE-2018-13367 exploitable without authentication?
Yes, CVE-2018-13367 can be exploited by unauthenticated attackers.
5
Which versions of FortiOS are affected by CVE-2018-13367?
FortiOS versions 6.2.3, 6.2.0 and earlier are affected by CVE-2018-13367.