An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
2018-05-25T16:29:00.230
2024-11-21T03:12:19.223
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortios | ≤ 5.2.13 | Yes |
Operating System | fortinet | fortios | ≤ 5.4.8 | Yes |
Operating System | fortinet | fortios | ≤ 5.6.2 | Yes |