An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
2025-01-14T14:15:31.490
2025-01-31T16:09:23.847
Analyzed
CVSSv3.1: 3.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortios | < 7.4.5 | Yes |
Operating System | fortinet | fortios | 7.6.0 | Yes |