CVE-2023-37935
https://notcve.org/view.php?id=CVE-2023-37935
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services. Un uso del método de solicitud GET con vulnerabilidad de cadenas de consulta confidenciales en Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 y 7.4.0 permite a un atacante ver contraseñas en texto plano de servicios remotos como RDP o VNC, si el atacante puede leer las solicitudes GET de esos servicios. • https://fortiguard.com/psirt/FG-IR-23-120 • CWE-598: Use of GET Request Method With Sensitive Query Strings •
CVE-2023-33301
https://notcve.org/view.php?id=CVE-2023-33301
An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host. Una vulnerabilidad de control de acceso inadecuado en Fortinet FortiOS 7.2.0 - 7.2.4 y 7.4.0 permite a un atacante acceder a un recurso restringido desde un host no confiable. • https://fortiguard.com/psirt/FG-IR-23-139 • CWE-284: Improper Access Control •