CVE-2021-32596

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
04/08/2021
Last modified:
10/08/2021

Description

A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords by means of precomputed tables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.4 (including)


References to Advisories, Solutions, and Tools