First published: Tue Oct 05 2021(Updated: )
An information disclosure vulnerability [CWE-200] in FortiAnalyzer and FortiManager VM may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | ||
Fortinet FortiManager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-21-112 is classified as high due to the possibility of an authenticated attacker unauthorizedly accessing FortiCloud credentials in cleartext.
To fix FG-IR-21-112, ensure that you upgrade to the latest versions of FortiAnalyzer and FortiManager as recommended by Fortinet.
The impact of FG-IR-21-112 can lead to unauthorized access to sensitive FortiCloud credentials, compromising security.
FG-IR-21-112 affects users of Fortinet FortiAnalyzer and FortiManager virtual machines that are vulnerable to information disclosure.
As of now, there is no public exploit for FG-IR-21-112, but the vulnerability is serious enough to warrant immediate action.