An exposure of sensitive information to an unauthorized...
Critical severity
Unreviewed
Published
Jan 13, 2026
to the GitHub Advisory Database
•
Updated Jan 13, 2026
Description
Published by the National Vulnerability Database
Jan 13, 2026
Published to the GitHub Advisory Database
Jan 13, 2026
Last updated
Jan 13, 2026
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.
References