CVE-2023-37935
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2023
Last modified:
07/11/2023
Description
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.0.12 (including) |
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 7.2.0 (including) | 7.2.5 (including) |
cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page