Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiAuthenticator 安全漏洞
Vulnerability Description
Fortinet FortiAuthenticator是美国飞塔(Fortinet)公司的系列安全认证软件,它可与FortiToken(双因子认证令牌)结合,向通过RADIUS或LDAP认证的第三方设备提供安全的双因子验证。 Fortinet FortiAuthenticator 3.0.0版本中存在安全漏洞,该漏洞源于程序使用明文记录PostgreSQL用户名和密码。远程攻击者可通过在debug/startup/ URI中读取日志利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A