A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-23-120 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-10-10 17:15
Updated : 2023-11-07 04:17
NVD link : CVE-2023-37935
Mitre link : CVE-2023-37935
CVE.ORG link : CVE-2023-37935
JSON object : View
Products Affected
fortinet
- fortios
CWE