CVE-2019-16157Sensitive Information Exposure in Fortinet Fortiweb

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 24

Description

An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5fortinet/fortinet_fortiweb6.2.0 and earlier

🔴Vulnerability Details

2
GHSA
GHSA-jxwq-w6v2-6v7q: An information exposure vulnerability in Fortinet FortiWeb 62022-05-24
CVEList
CVE-2019-16157: An information exposure vulnerability in Fortinet FortiWeb 62020-03-13

📋Vendor Advisories

1
Fortinet
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view...2020-03-13