Information Disclosure Vulnerability in Fortinet FortiOS Products
CVE-2024-32122

2.1LOW

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
8 April 2025

Summary

A significant vulnerability exists in Fortinet's FortiOS versions 7.2.0 and 7.2.1, where stored passwords are kept in a recoverable format. This flaw enables an attacker to manipulate the LDAP server IP, redirecting it to a malicious server. As a result, an attacker could potentially extract sensitive information, compromising the security posture of an organization. Immediate remediation is advised to mitigate the risk of unauthorized information disclosure.

Affected Version(s)

FortiOS 7.4.0 <= 7.4.7

FortiOS 7.2.0 <= 7.2.11

FortiOS 7.0.0 <= 7.0.17

References

CVSS V3.1

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.