CVE-2017-7738 Information
Feb 14, 2021
cve
Description
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2 5.4.0 to 5.4.5 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/102151 https://fortiguard.com/advisory/FG-IR-17-172
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: