A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
References
Link | Resource |
---|---|
http://fortiguard.com/advisory/FG-IR-16-050 | Not Applicable |
http://www.securityfocus.com/bid/94690 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1037394 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-03-30 07:59
Updated : 2017-07-27 18:29
NVD link : CVE-2016-7542
Mitre link : CVE-2016-7542
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
fortinet
- fortios