A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-23-120 |
![]() ![]() |
History
Thu, 19 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-19T20:22:22.682Z
Reserved: 2023-07-11T08:16:54.092Z
Link: CVE-2023-37935

Updated: 2024-08-02T17:23:27.995Z

Status : Modified
Published: 2023-10-10T17:15:12.267
Modified: 2024-11-21T08:12:30.057
Link: CVE-2023-37935

No data.