CVE-2019-16157

MEDIUM

Fortinet FortiWeb <6.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-19-269

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532 CWE-200
Status published
Products (1)
fortinet/fortiweb < 6.2.0
Published Mar 13, 2020
Tracked Since Feb 18, 2026