CVE-2022-35842Sensitive Information Exposure in Fortinet Fortios

Severity
7.5HIGHNVD
CNA3.7
EPSS
0.5%
top 34.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2

Description

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/fortios6.4.06.4.9+2
CVEListV5fortinet/fortinet_fortiosFortiOS 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xcfc-fhv2-9grh: An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 72022-11-02
CVEList
CVE-2022-35842: An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 72022-11-02

📋Vendor Advisories

1
Fortinet
Telnet on the SSL-VPN interface results in information leak2022-11-02
CVE-2022-35842 — Sensitive Information Exposure | cvebase