Sensitive Information Disclosure in Fortinet FortiAuthenticator
CVE-2015-1456
Currently unrated
Summary
Fortinet FortiAuthenticator 3.0.0 has a vulnerability that allows the storage of PostgreSQL usernames and passwords in cleartext format. This issue permits unauthorized access to sensitive information via logs located at debug/startup/. Remote administrators can exploit this flaw to gain critical insights into credentials, potentially compromising security and leading to unauthorized access to affected systems.
References
Timeline
Vulnerability published
Vulnerability Reserved