An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21135 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests. |
Fixes
Solution
Please upgrade to FortiOS version 7.4.2 or above Please upgrade to FortiOS version 7.2.6 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-224 |
|
History
Wed, 11 Dec 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortios |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortios |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-22T19:58:33.041Z
Reserved: 2024-01-19T08:23:28.612Z
Link: CVE-2024-23662
Updated: 2024-08-01T23:06:25.270Z
Status : Analyzed
Published: 2024-04-09T15:15:31.370
Modified: 2024-12-11T19:11:44.790
Link: CVE-2024-23662
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD