PT-2021-9842 · Fortinet · Fortiadc
Published
2021-11-02
·
Updated
2021-11-04
·
CVE-2020-15935
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiADC versions 5.4.3 and below
FortiADC versions 6.0.0 and below
Description
A cleartext storage of sensitive information in the GUI may allow a remote authenticated attacker to retrieve sensitive information, such as users' LDAP passwords and RADIUS shared secret, by deobfuscating the passwords entry fields.
Recommendations
For FortiADC versions 5.4.3 and below, update to a version above 5.4.3 to resolve the issue.
For FortiADC versions 6.0.0 and below, update to a version above 6.0.0 to resolve the issue.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiadc