FG-IR-18-232: Information disclosure through diagnose debug commands
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager, FortiAnalyzer, FortiPortal & FortiSwitch may allow an attacker which has obtained access to a restricted administrative account to obtain sensitive information via diagnose debug commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-18-232?
The severity of FG-IR-18-232 is considered critical due to the potential exposure of sensitive information.
How do I fix FG-IR-18-232?
To fix FG-IR-18-232, update your FortiManager, FortiAnalyzer, FortiPortal, and FortiSwitch to the latest patched version from Fortinet.
What products are affected by FG-IR-18-232?
FG-IR-18-232 affects FortiManager, FortiAnalyzer, FortiPortal, and FortiSwitch.
What type of vulnerability is FG-IR-18-232?
FG-IR-18-232 is an exposure of sensitive information to an unauthorized actor vulnerability.
Who can exploit FG-IR-18-232?
An attacker with access to a restricted administrative account may exploit FG-IR-18-232.