SB2021120720 - Information disclosure in FortiSandbox, FortiWeb and FortiADC



SB2021120720 - Information disclosure in FortiSandbox, FortiWeb and FortiADC

Published: December 7, 2021

Security Bulletin ID SB2021120720
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Required Cryptographic Step (CVE-ID: CVE-2021-32591)

CWE-ID: CWE-325 - Missing Required Cryptographic Step

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows an attacker to compromise users' passwords.

The vulnerability exists due to missing cryptographic steps in the function that encrypts users' LDAP and RADIUS credentials. An attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.


Remediation

Install update from vendor's website.