Information disclosure in FortiManager - CVE-2016-8495
Published: February 9, 2017 / Updated: February 15, 2017
FortiManager
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to incorrect validation of TLS certificates in FortiManager. A remote attacker from local network can try to access devices using affected software and obtain pre-shared encryption key.
Successful exploitation of the vulnerability may allow an attacker to gain access to passwords.