A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-23-120 |
History
Thu, 19 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2023-10-10T16:51:21.801Z
Updated: 2024-09-19T20:22:22.682Z
Reserved: 2023-07-11T08:16:54.092Z
Link: CVE-2023-37935
Vulnrichment
Updated: 2024-08-02T17:23:27.995Z
NVD
Status : Modified
Published: 2023-10-10T17:15:12.267
Modified: 2024-11-21T08:12:30.057
Link: CVE-2023-37935
Redhat
No data.