Sensitive Information Exposure in FortiOS SSL-VPN by Fortinet
CVE-2022-35842
3.7LOW
Summary
A vulnerability in FortiOS SSL-VPN could allow unauthorized access to sensitive information, including configuration settings for LDAP and SAML. This issue affects multiple versions of FortiOS, specifically those in the ranges of 7.2.0, 7.0.0 through 7.0.6, and 6.4.0 through 6.4.9. Consequently, a remote unauthenticated attacker might exploit this vulnerability to gather critical information that could aid in further attacks.
Affected Version(s)
Fortinet FortiOS FortiOS 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved