CVE-2022-41327: Fortinet FortiOS
Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.
Affected products
- Fortinet FortiOS: from 7.0.0, up to and including 7.0.8; from 7.2.0, up to and including 7.2.4
- Fortinet FortiProxy: from 7.0.0, up to and including 7.0.7; version 7.2.0 only; version 7.2.1 only
Published 2023-06-13. Last modified 2026-06-17.