FG-IR-23-224: Web server ETag exposure
Published Apr 9, 2024
·Updated
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS may allow an unauthenticated attacker to fingerprint the device version via HTTP requests.
Affected Software
4 affected componentsFixes available
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.5
Fortinet FortiOS>=7.0
Fortinet FortiOS>=6.4
Event History
Apr 9, 2024
Advisory Published
via FortiGuard·12:00 AM
Oct 23, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-23-224?
FG-IR-23-224 is classified as a medium severity vulnerability affecting FortiOS.
2
How do I fix FG-IR-23-224?
To fix FG-IR-23-224, upgrade FortiOS to version 7.4.2 or later for affected 7.4 versions, or to 7.2.6 or later for affected 7.2 versions.
3
Which FortiOS versions are affected by FG-IR-23-224?
FG-IR-23-224 affects FortiOS versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.5, 7.0 and 6.4.
4
Can an authenticated user be vulnerable to FG-IR-23-224?
Yes, FG-IR-23-224 can expose sensitive information even to authenticated users if not patched.
5
What type of vulnerability is FG-IR-23-224?
FG-IR-23-224 is an exposure of sensitive information to an unauthorized actor vulnerability.