CVE-2017-7738

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
13/12/2017
Last modified:
20/04/2025

Description

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortios:*:*:*:*:*:*:*:* 5.2 (including)
cpe:2.3:a:fortinet:fortios:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.5 (including)
cpe:2.3:a:fortinet:fortios:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.2 (including)