CVE-2024-32122

Severity CVSS v4.0:
Pending analysis
Type:
CWE-257 Storing Passwords in a Recoverable Format
Publication date:
08/04/2025
Last modified:
18/11/2025

Description

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.16 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.17 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.11 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.7 (including)


References to Advisories, Solutions, and Tools