#VU49278 Information disclosure in FortiOS - CVE-2020-29010
Published: January 5, 2021
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due FortiGate may allow a remote authenticated user to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. As a result, a remote user can obtain sensitive data from other VDOMs that include usernames, user groups, and IP addresses.