ID

VAR-201904-0615


CVE

CVE-2018-1360


TITLE

Fortinet FortiManager Vulnerable to information disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2019-004246

DESCRIPTION

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses. Fortinet FortiManager Contains an information disclosure vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Fortinet FortiManager is prone to an information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. Fortinet FortiManager versions 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 are vulnerable. Fortinet FortiManager is a centralized network security management platform developed by Fortinet. The platform supports centralized management of any number of Fortinet devices, and can group devices into different management domains (ADOMs) to further simplify multi-device security deployment and management

Trust: 1.98

sources: NVD: CVE-2018-1360 // JVNDB: JVNDB-2019-004246 // BID: 108079 // VULHUB: VHN-123675

AFFECTED PRODUCTS

vendor:fortinetmodel:fortimanagerscope:eqversion:5.4.1

Trust: 2.1

vendor:fortinetmodel:fortimanagerscope:eqversion:5.4.0

Trust: 1.8

vendor:fortinetmodel:fortimanagerscope:lteversion:5.2.7

Trust: 1.0

vendor:fortinetmodel:fortimanagerscope:gteversion:5.2.0

Trust: 1.0

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.0 to 5.2.7

Trust: 0.8

vendor:fortinetmodel:fortimanagerscope:eqversion:5.4

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.7

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.6

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.5

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.2

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.1

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.4

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:eqversion:5.2.3

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:neversion:5.4.2

Trust: 0.3

vendor:fortinetmodel:fortimanagerscope:neversion:5.2.8

Trust: 0.3

sources: BID: 108079 // JVNDB: JVNDB-2019-004246 // NVD: CVE-2018-1360

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-1360
value: HIGH

Trust: 1.0

NVD: CVE-2018-1360
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201904-1088
value: HIGH

Trust: 0.6

VULHUB: VHN-123675
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-1360
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-123675
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-1360
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-123675 // JVNDB: JVNDB-2019-004246 // CNNVD: CNNVD-201904-1088 // NVD: CVE-2018-1360

PROBLEMTYPE DATA

problemtype:CWE-319

Trust: 1.1

problemtype:CWE-200

Trust: 0.9

sources: VULHUB: VHN-123675 // JVNDB: JVNDB-2019-004246 // NVD: CVE-2018-1360

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-1088

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201904-1088

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-004246

PATCH

title:FG-IR-18-051url:https://fortiguard.com/advisory/FG-IR-18-051

Trust: 0.8

title:Fortinet FortiManager Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91934

Trust: 0.6

sources: JVNDB: JVNDB-2019-004246 // CNNVD: CNNVD-201904-1088

EXTERNAL IDS

db:NVDid:CVE-2018-1360

Trust: 2.8

db:BIDid:108079

Trust: 2.0

db:JVNDBid:JVNDB-2019-004246

Trust: 0.8

db:CNNVDid:CNNVD-201904-1088

Trust: 0.7

db:AUSCERTid:ESB-2019.1434

Trust: 0.6

db:VULHUBid:VHN-123675

Trust: 0.1

sources: VULHUB: VHN-123675 // BID: 108079 // JVNDB: JVNDB-2019-004246 // CNNVD: CNNVD-201904-1088 // NVD: CVE-2018-1360

REFERENCES

url:http://www.securityfocus.com/bid/108079

Trust: 2.3

url:https://fortiguard.com/advisory/fg-ir-18-051

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-1360

Trust: 1.4

url:http://www.fortinet.com/

Trust: 0.9

url:https://fortiguard.com/psirt/fg-ir-18-051

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-1360

Trust: 0.8

url:https://vigilance.fr/vulnerability/fortimanager-information-disclosure-via-rest-api-json-responses-29117

Trust: 0.6

url:https://www.auscert.org.au/bulletins/79762

Trust: 0.6

sources: VULHUB: VHN-123675 // BID: 108079 // JVNDB: JVNDB-2019-004246 // CNNVD: CNNVD-201904-1088 // NVD: CVE-2018-1360

CREDITS

Pavel German.

Trust: 0.9

sources: BID: 108079 // CNNVD: CNNVD-201904-1088

SOURCES

db:VULHUBid:VHN-123675
db:BIDid:108079
db:JVNDBid:JVNDB-2019-004246
db:CNNVDid:CNNVD-201904-1088
db:NVDid:CVE-2018-1360

LAST UPDATE DATE

2024-08-14T14:45:26.106000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-123675date:2019-10-03T00:00:00
db:BIDid:108079date:2019-04-23T00:00:00
db:JVNDBid:JVNDB-2019-004246date:2019-05-29T00:00:00
db:CNNVDid:CNNVD-201904-1088date:2019-10-08T00:00:00
db:NVDid:CVE-2018-1360date:2019-10-03T00:03:26.223

SOURCES RELEASE DATE

db:VULHUBid:VHN-123675date:2019-04-25T00:00:00
db:BIDid:108079date:2019-04-23T00:00:00
db:JVNDBid:JVNDB-2019-004246date:2019-05-29T00:00:00
db:CNNVDid:CNNVD-201904-1088date:2019-04-24T00:00:00
db:NVDid:CVE-2018-1360date:2019-04-25T18:29:00.333