PT-2024-4152 · Fortinet · Fortiproxy+1
Published
2024-06-11
·
Updated
2024-10-04
·
CVE-2024-21754
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions prior to 7.4.4
FortiOS version 7.2 and earlier
FortiOS version 7.0 and earlier
FortiOS version 6.4 and earlier
FortiProxy versions prior to 7.4.3
FortiProxy version 7.2 and earlier
FortiProxy version 7.0 and earlier
FortiProxy version 2.0 and earlier
Description
The issue is related to a use of password hash with insufficient computational effort, which may allow a privileged attacker with super-admin profile and CLI access to decrypt the backup file. This could potentially be exploited by an attacker to gain unauthorized access to sensitive data.
Recommendations
For FortiOS versions prior to 7.4.4, update to version 7.4.4 or later to resolve the issue.
For FortiOS version 7.2 and earlier, update to a version later than 7.2 to resolve the issue.
For FortiOS version 7.0 and earlier, update to a version later than 7.0 to resolve the issue.
For FortiOS version 6.4 and earlier, update to a version later than 6.4 to resolve the issue.
For FortiProxy versions prior to 7.4.3, update to version 7.4.3 or later to resolve the issue.
For FortiProxy version 7.2 and earlier, update to a version later than 7.2 to resolve the issue.
For FortiProxy version 7.0 and earlier, update to a version later than 7.0 to resolve the issue.
For FortiProxy version 2.0 and earlier, update to a version later than 2.0 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortiproxy