An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL.
2025-06-10T17:21:16.550
2025-07-22T17:52:45.433
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisase | 25.1.75 | Yes |
Operating System | fortinet | fortios | < 7.4.8 | Yes |
Operating System | fortinet | fortios | 7.6.0 | Yes |