Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-32596


A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords by means of precomputed tables.


Published

2021-08-04T16:15:08.353

Last Modified

2024-11-21T06:07:20.863

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-916

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiportal ≤ 6.0.4 Yes

References