Cryptographic Key Vulnerability in FortiAuthenticator by Fortinet
CVE-2021-24005
4MEDIUM
What is CVE-2021-24005?
The vulnerability involves the use of hard-coded cryptographic keys within FortiAuthenticator, enabling unauthorized access to sensitive configuration files and debug logs. Attackers with access to these files or the command-line interface (CLI) can decrypt protected data, citing knowledge of the embedded key. This flaw poses significant risks for data security and privacy, potentially leading to data breaches and unauthorized information disclosure.
Affected Version(s)
FortiAuthenticator FortiAuthenticator versions before 6.3.0.