CVE-2023-37935: Plain-text credentials in GET request via SSL VPN web portal
A use of GET request method with sensitive query strings vulnerability [CWE-598] in the FortiOS SSL VPN component may allow an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services (found in logs, referers, caches, etc...)
Other sources
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-37935?
CVE-2023-37935 is a vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 that allows an attacker to view plaintext passwords of remote services if they can read the GET requests to those services.
How does the CVE-2023-37935 vulnerability impact Fortinet FortiOS?
The CVE-2023-37935 vulnerability allows an attacker to view plaintext passwords of remote services in Fortinet FortiOS if they can read the GET requests to those services.
What is the severity level of CVE-2023-37935?
The severity level of CVE-2023-37935 is high with a severity value of 7.5.
Which versions of Fortinet FortiOS are affected by CVE-2023-37935?
Fortinet FortiOS versions 7.0.0 - 7.0.12, 7.2.0 - 7.2.5, and 7.4.0 are affected by CVE-2023-37935.
How can I fix the CVE-2023-37935 vulnerability in Fortinet FortiOS?
To fix the CVE-2023-37935 vulnerability, it is recommended to update Fortinet FortiOS to a version that is not affected by the vulnerability.