CVE-2021-24005

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
06/07/2021
Last modified:
08/07/2021

Description

Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:* 6.0.0 (including) 6.3.0 (excluding)


References to Advisories, Solutions, and Tools