Sensitive Information Exposure in FortiOS SSL-VPN by Fortinet
CVE-2022-35842

3.7LOW

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
2 November 2022

Summary

A vulnerability in FortiOS SSL-VPN could allow unauthorized access to sensitive information, including configuration settings for LDAP and SAML. This issue affects multiple versions of FortiOS, specifically those in the ranges of 7.2.0, 7.0.0 through 7.0.6, and 6.4.0 through 6.4.9. Consequently, a remote unauthenticated attacker might exploit this vulnerability to gather critical information that could aid in further attacks.

Affected Version(s)

Fortinet FortiOS FortiOS 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.