Information disclosure in FortiOS - CVE-2018-13366
Published: November 29, 2018
Vulnerability identifier: #VU16173
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-13366
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote to obtain potentially sensitive information.
The weakness exists due to Fortigate PPTP service reveals serial number of FortiGate in the hostname field defined in connection control setup packets of PPTP protocol. A remote attacker can gain access to arbitrary data.
The weakness exists due to Fortigate PPTP service reveals serial number of FortiGate in the hostname field defined in connection control setup packets of PPTP protocol. A remote attacker can gain access to arbitrary data.
Affected software
FortiOS
Opensuse
JBoss Enterprise Application Platform
Opensuse
JBoss Enterprise Application Platform
How to mitigate CVE-2018-13366
Update to version 6.0.2.
FortiOS - update to 6.0.2
External References
Related Security Bulletins
- Information disclosure vulnerabilities in Fortinet FortiOS
- OpenSUSE Linux update for tomcat
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.21
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.21
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.21