← back
CVE-2022-41327

CVE-2022-41327

CVSS 7.6 HIGHEPSS 0.1%CWE-319
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.6EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Jun 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →