A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortimanager | Fortinet | 5.2.0 (including) | 5.2.7 (including) |
Fortimanager | Fortinet | 5.4.0 (including) | 5.4.0 (including) |
Fortimanager | Fortinet | 5.4.1 (including) | 5.4.1 (including) |