CVE-2018-1360
published 2019-04-25CVE-2018-1360: A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated…
PriorityP342high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
0.86%
54.3th percentile
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 5.2.0 – 5.2.7 | — |
| fortinet | fortinet | — | — |
| fortinet_inc | fortinet_fortimanager | — | — |
| fortinet_inc | fortinet_fortimanager | — | — |
| fortinet_inc | fortinet_fortimanager | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and...
vendor_fortinet·2019-04-25·CVSS 8.1
CVE-2018-1360 [HIGH] CWE-319 A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and...
FG-IR-18-051: A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and...
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
CVEs: CVE-2018-1360
CWEs: CWE-319
CVSS: 8.1 (high)
Affected products: FortiManager, Fortinet
GHSA
GHSA-mw85-7jc9-5968: A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5
ghsa_unreviewed·2022-05-24
CVE-2018-1360 [HIGH] CWE-319 GHSA-mw85-7jc9-5968: A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-25
Published