A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-20-222 | Patch Vendor Advisory |
https://fortiguard.com/advisory/FG-IR-20-222 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/advisory/FG-IR-20-222 - Patch, Vendor Advisory |
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
Information
Published : 2021-12-08 12:15
Updated : 2024-11-21 06:07
NVD link : CVE-2021-32591
Mitre link : CVE-2021-32591
CVE.ORG link : CVE-2021-32591
JSON object : View
Products Affected
fortinet
- fortiweb
- fortisandbox
- fortimail
- fortiadc
CWE