CVE-2023-37935Use of GET Request Method With Sensitive Query Strings in Fortinet Fortios

Severity
7.5HIGHNVD
CNA6.5
EPSS
0.2%
top 58.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10

Description

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5fortinet/fortios7.2.07.2.5+2
NVDfortinet/fortios7.0.07.0.12+2

🔴Vulnerability Details

2
CVEList
CVE-2023-37935: A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 72023-10-10
GHSA
GHSA-3gmg-v9xp-m3jg: A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 72023-10-10

📋Vendor Advisories

1
Fortinet
Plain-text credentials in GET request via SSL VPN web portal2023-10-10
CVE-2023-37935 — Fortinet Fortios vulnerability | cvebase