CVE-2022-43954: Medium severity fortinet fortiportal vulnerability
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-43954?
CVE-2022-43954 is an insertion of sensitive information into log file vulnerability in the FortiPortal management interface 7.0.0 through 7.0.2.
How does CVE-2022-43954 impact FortiPortal?
CVE-2022-43954 may allow a remote authenticated attacker to read other devices' passwords in the audit log page of FortiPortal.
What is the severity of CVE-2022-43954?
CVE-2022-43954 has a severity rating of medium, with a CVSS score of 6.5.
Which versions of FortiPortal are affected by CVE-2022-43954?
CVE-2022-43954 affects FortiPortal versions 7.0.0, 7.0.1, and 7.0.2.
How can I mitigate the vulnerability of CVE-2022-43954?
To mitigate CVE-2022-43954, it is recommended to upgrade FortiPortal to a version that includes a fix for the vulnerability and follow any additional guidance provided by the vendor.