4.4

CVE-2024-21754

A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.

Data is provided by the National Vulnerability Database (NVD)
FortinetFortiproxy Version >= 2.0.0 <= 2.0.14
FortinetFortiproxy Version >= 7.0.0 <= 7.0.18
FortinetFortiproxy Version >= 7.2.0 <= 7.2.11
FortinetFortiproxy Version >= 7.4.0 < 7.4.3
FortinetFortios Version >= 6.4.0 <= 6.4.15
FortinetFortios Version >= 7.0.0 <= 7.0.15
FortinetFortios Version >= 7.2.0 < 7.2.9
FortinetFortios Version >= 7.4.0 < 7.4.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.25% 0.883
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
psirt@fortinet.com 1.8 0.3 1.4
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.