Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
Fortinet FortiSwitch和FortiWeb数据伪造问题漏洞
Vulnerability Description
Fortinet FortiWeb和FortiSwitch都是美国飞塔(Fortinet)公司的产品。Fortinet FortiWeb是一款Web应用层防火墙,它能够阻断如跨站点脚本、SQL注入、Cookie中毒、schema中毒等攻击的威胁,保证Web应用程序的安全性并保护敏感的数据库内容。FortiSwitch是一款交换机产品,它最大的优点是可以由防火墙统一管理,在一个窗口下就可以用图形界面管理整个局域网络。 Fortinet FortiWeb 6.4 所有版本、6.3.16 及之前版本版本、6.2
CVSS Information
N/A
Vulnerability Type
N/A