CVE-2022-35842 LOW

CVE-2022-35842

Vendor Fortinet
Product Fortinet FortiOS
Published November 2, 2022
Last update October 22, 2024

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X

What the vulnerability does

01Description

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.

Key dates

02Disclosure timeline

November 2, 2022 CVE published
October 22, 2024 Record updated