Description
An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
E
F
RL
O
RC
Changed
Affected products
- fortinet / Fortinet FortiManager, FortiAnalyzerFortiManager 7.0.0, 6.4.6; FortiAnalyzer 7.0.0, 6.4.6 – FortiManager 7.0.0, 6.4.6; FortiAnalyzer 7.0.0, 6.4.6