A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-20-222 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-12-08 04:15
Updated : 2021-12-10 14:35
NVD link : CVE-2021-32591
Mitre link : CVE-2021-32591
JSON object : View
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Products Affected
fortinet
- fortiadc
- fortiweb
- fortisandbox
- fortimail