First published: Tue Apr 09 2024(Updated: )
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS may allow an unauthenticated attacker to fingerprint the device version via HTTP requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.4.0<=7.4.1 | |
Fortinet FortiOS | >=7.2.0<=7.2.5 | |
Fortinet FortiOS | >=7.0 | |
Fortinet FortiOS | >=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
FG-IR-23-224 is classified as a medium severity vulnerability affecting FortiOS.
To fix FG-IR-23-224, upgrade FortiOS to version 7.4.2 or later for affected 7.4 versions, or to 7.2.6 or later for affected 7.2 versions.
FG-IR-23-224 affects FortiOS versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.5, 7.0 and 6.4.
Yes, FG-IR-23-224 can expose sensitive information even to authenticated users if not patched.
FG-IR-23-224 is an exposure of sensitive information to an unauthorized actor vulnerability.