CVE-2018-9185: Infoleak
Published Jul 5, 2018
·Updated
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
Affected Software
1 affected component
Fortinet FortiOS<=6.0.0
Event History
Jul 5, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9185?
CVE-2018-9185 has been classified as a high severity information disclosure vulnerability.
2
How do I fix CVE-2018-9185?
To mitigate CVE-2018-9185, upgrade to FortiOS version 6.0.1 or later.
3
What kind of information is exposed by CVE-2018-9185?
CVE-2018-9185 exposes users' web portal login credentials through a JavaScript file sent to the client.
4
Which FortiOS versions are affected by CVE-2018-9185?
CVE-2018-9185 affects FortiOS versions 6.0.0 and below.
5
Does CVE-2018-9185 affect functionalities of FortiOS?
CVE-2018-9185 primarily affects the security of user credentials but does not impact the core functionalities of FortiOS.