First published: Tue Mar 07 2023(Updated: )
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.x, 6.0.x allows an attacker which has obtained access to a restricted administrative account to obtain sensitive information via `diagnose debug` commands.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=5.6.0<=5.6.11 | |
Fortinet FortiAnalyzer | >=6.0.0<=6.0.4 | |
Fortinet FortiManager | >=5.6.0<=5.6.11 | |
Fortinet FortiManager | >=6.0.0<=6.0.4 | |
Fortinet FortiPortal | >=4.1.0<=4.1.2 | |
Fortinet FortiPortal | >=4.2.0<=4.2.2 | |
Fortinet FortiPortal | >=5.0.0<=5.0.3 | |
Fortinet FortiPortal | >=5.1.0<=5.1.2 | |
Fortinet FortiPortal | >=5.2.0<=5.2.6 | |
Fortinet FortiPortal | >=5.3.0<=5.3.8 | |
Fortinet FortiPortal | >=6.0.0<=6.0.9 | |
Fortinet FortiSwitch | >=6.0.0<=6.0.7 | |
Fortinet FortiSwitch | >=6.2.0<=6.2.7 | |
Fortinet FortiSwitch | >=6.4.0<=6.4.10 | |
Fortinet FortiSwitch | >=7.0.0<=7.0.4 |
Upgrade to FortiManager version 6.0.5 and above, Upgrade to FortiManager version 6.2.0 and above. Upgrade to FortiAnalyzer version 6.0.5 and above, Upgrade to FortiAnalyzer version 6.2.0 and above. Upgrade to FortiPortal version 6.0.10 and above. Upgrade to FortiSwitch version 6.4.11 and above, Upgrade to FortiSwitch version 7.0.5 and above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this exposure of sensitive information vulnerability is CVE-2022-27490.
The affected software for this vulnerability includes Fortinet FortiAnalyzer (version 5.6.0 through 5.6.11), Fortinet FortiManager (version 5.6.0 through 5.6.11), Fortinet FortiPortal (version 4.1.0 through 4.1.2), Fortinet FortiPortal (version 4.2.0 through 4.2.2), Fortinet FortiPortal (version 5.0.0 through 5.0.3), Fortinet FortiPortal (version 5.1.0 through 5.1.2), Fortinet FortiPortal (version 5.2.0 through 5.2.6), Fortinet FortiPortal (version 5.3.0 through 5.3.8), Fortinet FortiPortal (version 6.0.0 through 6.0.9), Fortinet FortiSwitch (version 6.0.0 through 6.0.7), Fortinet FortiSwitch (version 6.2.0 through 6.2.7), Fortinet FortiSwitch (version 6.4.0 through 6.4.10), and Fortinet FortiSwitch (version 7.0.0 through 7.0.4).
The severity rating for this vulnerability is medium, with a severity value of 6.5.
An unauthorized actor can exploit this vulnerability to gain access to sensitive information.
Yes, it is recommended to update to the latest version of the affected software to mitigate this vulnerability.