Cryptographic Vulnerability in Fortinet Products Impacting User Credential Security
CVE-2021-32591
5.3MEDIUM
What is CVE-2021-32591?
A vulnerability exists in Fortinet products due to missing cryptographic steps in the function that encrypts user credentials for LDAP and RADIUS services. This oversight may enable attackers with access to the password store to compromise the confidentiality of sensitive information, thereby potentially exposing user data to unauthorized access. The affected versions include FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, and FortiMail 7.0.1 and earlier.
Affected Version(s)
Fortinet FortiSandbox FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier