This security bulletin contains one low risk vulnerability.
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to usage of hard-coded cryptographic keys to encrypt configuration files, debug logs and password data. A local user with access to the files or the CLI configuration can decrypt the sensitive data.Mitigation
Install updates from vendor's website.Vulnerable software versions
FortiAuthenticator: 5.0.0 - 6.2.1Fixed software versions
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?