SB2017081038 - Information disclosure in Fortinet, FortiOS
Published: August 10, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2017-3130)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
Remediation
Install update from vendor's website.