CVE-2022-27490

MEDIUM

Fortinet Fortianalyzer < 5.6.11 - Information Disclosure

Title source: rule
STIX 2.1

Description

A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.x, 6.0.x allows an attacker which has obtained access to a restricted administrative account to obtain sensitive information via `diagnose debug` commands.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0039
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (4)
fortinet/fortianalyzer 5.6.0 - 5.6.11
fortinet/fortimanager 5.6.0 - 5.6.11
fortinet/fortiportal 4.1.0 - 4.1.2
fortinet/fortiswitch 6.0.0 - 6.0.7
Published Mar 07, 2023
Tracked Since Feb 18, 2026