4.4
CVE-2024-21754
- EPSS 5.71%
- Veröffentlicht 11.06.2024 15:16:03
- Zuletzt bearbeitet 21.11.2024 08:54:56
- Quelle psirt@fortinet.com
- CVE-Watchlists
- Unerledigt
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortiproxy Version >= 2.0.0 <= 2.0.14
Fortinet ≫ Fortiproxy Version >= 7.0.0 <= 7.0.18
Fortinet ≫ Fortiproxy Version >= 7.2.0 <= 7.2.11
Fortinet ≫ Fortiproxy Version >= 7.4.0 < 7.4.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.71% | 0.901 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| psirt@fortinet.com | 1.8 | 0.3 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
|
CWE-916 Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.