HIGH
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system
Published Jun 16, 2020
7.5
HIGHCVSS 3.1
EPSS 0.99%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.