Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-21754


A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.


Published

2024-06-11T15:16:03.433

Last Modified

2024-11-21T08:54:56.877

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 1.8 (LOW)

Weaknesses
  • Type: Primary
    CWE-916

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy ≤ 2.0.14 Yes
Application fortinet fortiproxy ≤ 7.0.18 Yes
Application fortinet fortiproxy ≤ 7.2.11 Yes
Application fortinet fortiproxy < 7.4.3 Yes
Operating System fortinet fortios ≤ 6.4.15 Yes
Operating System fortinet fortios ≤ 7.0.15 Yes
Operating System fortinet fortios < 7.2.9 Yes
Operating System fortinet fortios < 7.4.4 Yes

References