FG-IR-22-455: SMTP password ciphertext exposure in Log
Published Jun 12, 2023
·Updated
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS / FortiProxy log events may allow a remote authenticated attacker to read certain passwords in ciphertext.
Affected Software
8 affected componentsFixes available
Fortinet FortiOS>=7.2.0<=7.2.5
Fortinet FortiOS>=7.0.0<=7.0.15
Fortinet FortiOS>=6.4
Fortinet FortiOS>=6.2
Fortinet FortiOS>=6.0
Fortinet FortiProxy>=7.2.0<=7.2.1
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy>=2.0.0<=2.0.12
Event History
Jun 12, 2023
Advisory Published
via FortiGuard·12:00 AM
Oct 25, 2024
Advisory Published
via FortiGuard·11:55 PM
Frequently Asked Questions
1
What is the severity of FG-IR-22-455?
The severity of FG-IR-22-455 is rated based on the potential exposure of sensitive information through log files.
2
How do I fix FG-IR-22-455?
To fix FG-IR-22-455, upgrade to FortiOS version 7.2.6 or later, or FortiProxy version 7.2.2 or later, according to your specific software.
3
What kind of information is affected by FG-IR-22-455?
FG-IR-22-455 may expose certain passwords in ciphertext to remote authenticated attackers through log files.
4
Which versions of FortiOS are impacted by FG-IR-22-455?
FortiOS versions from 7.0.0 to 7.2.5 and various earlier versions are affected by FG-IR-22-455.
5
Is there a workaround for FG-IR-22-455 before patching?
Currently, no specific workarounds are documented for FG-IR-22-455; patching is recommended.