Information Disclosure Vulnerability in Fortinet FortiOS Products
CVE-2024-32122
2.1LOW
Summary
A significant vulnerability exists in Fortinet's FortiOS versions 7.2.0 and 7.2.1, where stored passwords are kept in a recoverable format. This flaw enables an attacker to manipulate the LDAP server IP, redirecting it to a malicious server. As a result, an attacker could potentially extract sensitive information, compromising the security posture of an organization. Immediate remediation is advised to mitigate the risk of unauthorized information disclosure.
Affected Version(s)
FortiOS 7.4.0 <= 7.4.7
FortiOS 7.2.0 <= 7.2.11
FortiOS 7.0.0 <= 7.0.17
References
CVSS V3.1
Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved