An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortianalyzer | Fortinet | * | 6.4.7 (excluding) |
Fortianalyzer | Fortinet | 7.0.0 (including) | 7.0.1 (including) |
Fortimanager | Fortinet | * | 6.4.7 (excluding) |
Fortimanager | Fortinet | 7.0.0 (including) | 7.0.1 (excluding) |