An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-17-162 | vendor advisory |
http://www.securityfocus.com/bid/100205 | third party advisory vdb entry |