PT-2025-15426 · Fortinet · Fortios
Published
2025-04-08
·
Updated
2025-11-18
·
CVE-2024-32122
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Fortinet FortiOS versions 7.2.0 through 7.2.1
Description:
The issue allows an attacker to disclose information by modifying the LDAP server IP to point to a malicious server, due to passwords being stored in a recoverable format.
Recommendations:
For Fortinet FortiOS versions 7.2.0 through 7.2.1, consider restricting access to the LDAP server configuration to minimize the risk of exploitation. As a temporary workaround, restrict modifications to the LDAP server IP until a patch is available.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios