PSIRT Advisories

Multiple Products - Retrieval of sensitive information in cleartext via GUI

Summary

A cleartext storage of sensitive information in the GUI of FortiADC, FortiSIEM, FortiDDoS, FortiDDoS-CM and FortiDDoS-F may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords, RADIUS shared secret and the Elastic Cloud database password by deobfuscating the passwords entry fields.

Affected Products

FortiADC versions 6.0.0.
FortiADC versions 5.4.3 and below.
FortiSIEM versions 6.2.1 and below.
FortiSIEM versions 6.1.2 and below.
FortiSIEM versions 5.x.x.
FortiDDoS versions 4.2.1 through 5.4.2..
FortiDDoS-CM versions 4.7.0 through 5.4.1.
FortiDDoS-F versions 6.1.4 and below.
FortiDDoS-F versions 6.0.0.


 

Solutions

Please upgrade to FortiADC versions 5.4.4 or above.
Please upgrade to FortiADC versions 6.0.1 or above.
Please upgrade to FortiSIEM 6.3.0 or above.
Please upgrade to FortiDDoS 5.5.0 or above.
Please upgrade to FortiDDoS-F 6.2.0 or above.

Acknowledgement

Fortinet is pleased to thank Harish Chowdary for reporting this vulnerability under responsible disclosure.