PSIRT Advisory

FortiOS SSL VPN user credential plaintext storage


A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

To successfully exploit this weakness, another unrelated weakness (eg: a system file leaking vulnerability) would therefore need to be exploited first.


Information Disclosure

Affected Products

FortiOS all versions below 6.2.3


Upgrade to FortiOS 6.2.3