Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37935


A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.


Published

2023-10-10T17:15:12.267

Last Modified

2024-11-21T08:12:30.057

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-598
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortios ≤ 7.0.12 Yes
Operating System fortinet fortios ≤ 7.2.5 Yes
Operating System fortinet fortios 7.4.0 Yes

References