4.9

CVE-2016-7542

A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiOS Version 5.2.0
Fortinet ≫ FortiOS Version 5.2.1
Fortinet ≫ FortiOS Version 5.2.2
Fortinet ≫ FortiOS Version 5.2.3
Fortinet ≫ FortiOS Version 5.2.4
Fortinet ≫ FortiOS Version 5.2.5
Fortinet ≫ FortiOS Version 5.2.6
Fortinet ≫ FortiOS Version 5.2.7
Fortinet ≫ FortiOS Version 5.2.8
Fortinet ≫ FortiOS Version 5.2.9
Fortinet ≫ FortiOS Version 5.4.0
Fortinet ≫ FortiOS Version 5.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.54% 0.716
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://fortiguard.com/advisory/FG-IR-16-050
Not Applicable
http://www.securityfocus.com/bid/94690
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037394