An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinets FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortiweb | Fortinet | 6.2.0 (including) | 6.2.3 (including) |
Fortiweb | Fortinet | 6.3.0 (including) | 6.3.4 (including) |