First published: Thu Feb 16 2023(Updated: )
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPortal | =7.0.0 | |
Fortinet FortiPortal | =7.0.1 | |
Fortinet FortiPortal | =7.0.2 |
Please upgrade to FortiPortal version 7.0.3 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43954 is an insertion of sensitive information into log file vulnerability in the FortiPortal management interface 7.0.0 through 7.0.2.
CVE-2022-43954 may allow a remote authenticated attacker to read other devices' passwords in the audit log page of FortiPortal.
CVE-2022-43954 has a severity rating of medium, with a CVSS score of 6.5.
CVE-2022-43954 affects FortiPortal versions 7.0.0, 7.0.1, and 7.0.2.
To mitigate CVE-2022-43954, it is recommended to upgrade FortiPortal to a version that includes a fix for the vulnerability and follow any additional guidance provided by the vendor.