PT-2021-3713 · Fortinet · Fortiauthenticator

Published

2021-05-30

·

Updated

2021-07-08

·

CVE-2021-24005

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiAuthenticator versions prior to 6.3.0
Description The issue is related to the use of hard-coded cryptographic keys in FortiAuthenticator, which can allow an attacker with access to certain files or the CLI configuration to decrypt sensitive data. This is possible because the system uses predetermined cryptographic keys to encrypt configuration files and debug logs.
Recommendations For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to configuration files and the CLI configuration to minimize the risk of exploitation. Avoid using the hard-coded cryptographic keys in the affected configuration files and debug logs until the issue is resolved.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03953
CVE-2021-24005

Affected Products

Fortiauthenticator