Fortinet Products Exposure of Sensitive Information Vulnerability Allowing Unauthorized Access to Software Version Details

Vulnerability

A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in multiple Fortinet products. This issue affects FortiDDoS versions 5.4.0, 5.3.2 and below, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0, 4.5.0, 4.4.2 and below, as well as FortiDDoS-CM versions 5.3.0, 5.2.0, 5.1.0, 5.0.0, and 4.7.0. Additionally, FortiVoice versions 6.0.6 and below, FortiRecorder versions 6.0.3 and below, and FortiMail versions 6.4.1 and below, 6.2.4 and below, and 6.0.9 and below are also affected. The vulnerability allows remote, unauthenticated attackers to obtain potentially sensitive software version information by reading a JavaScript file.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive software version information, which could be used to identify potential vulnerabilities or weaknesses in the system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
7.6
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.