CVE-2022-41327: High severity fortinet fortiproxy ssl vpn webmode vulnerability
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-41327?
CVE-2022-41327 is a cleartext transmission of sensitive information vulnerability in Fortinet FortiOS versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.8, as well as FortiProxy versions 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8.
How does CVE-2022-41327 affect Fortinet FortiOS and FortiProxy?
CVE-2022-41327 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in cleartext, potentially exposing sensitive information.
What is the severity of CVE-2022-41327?
CVE-2022-41327 has a severity value of 4.4, which is considered high.
How can I fix CVE-2022-41327?
To fix CVE-2022-41327, it is recommended to upgrade to the latest version of Fortinet FortiOS or FortiProxy, as specified in the vendor's security advisory.
Where can I find more information about CVE-2022-41327?
You can find more information about CVE-2022-41327 in the vendor's security advisory at the following link: [Fortinet Advisory](https://fortiguard.com/psirt/FG-IR-22-380).