CVE-2021-26113

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
06/04/2022
Last modified:
13/04/2022

Description

A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiwan:*:*:*:*:*:*:*:* 4.5.9 (excluding)


References to Advisories, Solutions, and Tools