SB2016120501 - Administrative password hash disclosure in FortiOS
Published: December 5, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2016-7542)
The vulnerability allows a remote attacker to obtain hash of local administrator.
The vulnerability exists due to unknown error. A remote attacker with unspecified privileges may be able to obtain password hash of local administrator. It is unclear, if the attacker should be authenticated.
Successful exploitation of the vulnerability may allow an attacker to brute-force password hash and obtain administrative privileges on vulnerable device.
Remediation
Install update from vendor's website.