CVE-2023-37935

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2023
Last modified:
07/11/2023

Description

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.12 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.5 (including)
cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools