First published: Thu Jul 05 2018(Updated: )
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | <=6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9185 has been classified as a high severity information disclosure vulnerability.
To mitigate CVE-2018-9185, upgrade to FortiOS version 6.0.1 or later.
CVE-2018-9185 exposes users' web portal login credentials through a JavaScript file sent to the client.
CVE-2018-9185 affects FortiOS versions 6.0.0 and below.
CVE-2018-9185 primarily affects the security of user credentials but does not impact the core functionalities of FortiOS.