5.3

CVE-2021-32591

A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.

Data is provided by the National Vulnerability Database (NVD)
FortinetFortiadc Version >= 5.0.0 <= 5.4.4
FortinetFortiadc Version >= 6.0.0 <= 6.0.3
FortinetFortiadc Version >= 6.1.0 <= 6.1.3
FortinetFortiadc Version6.2.0
FortinetFortiadc Version6.2.1
FortinetFortimail Version >= 5.0 <= 5.6.3
FortinetFortimail Version >= 6.0.0 <= 6.0.11
FortinetFortimail Version >= 6.2.0 <= 6.2.7
FortinetFortimail Version >= 6.4.0 <= 6.4.5
FortinetFortimail Version7.0.0
FortinetFortimail Version7.0.1
FortinetFortisandbox Version >= 3.2.0 <= 3.2.2
FortinetFortisandbox Version4.0.0
FortinetFortiweb Version >= 5.7.0 <= 5.7.3
FortinetFortiweb Version >= 5.8.0 <= 5.8.7
FortinetFortiweb Version >= 6.0.0 <= 6.0.7
FortinetFortiweb Version >= 6.1.0 <= 6.1.2
FortinetFortiweb Version >= 6.2.0 <= 6.2.4
FortinetFortiweb Version >= 6.3.0 <= 6.3.11
FortinetFortiweb Version5.9.0
FortinetFortiweb Version5.9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.344
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
psirt@fortinet.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N