Security Advisory

CVE-2023-37935

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-10-10 16:51:21
Last updated 2024-09-19 20:22:22
Assigner fortinet
CVSS score 6.5
State PUBLISHED

Description

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.