Information disclosure in FortiOS - CVE-2016-7542

 

Information disclosure in FortiOS - CVE-2016-7542

Published: December 2, 2016 / Updated: December 5, 2016


Vulnerability identifier: #VU1194
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-7542
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Fortinet, Inc
Affected software:
FortiOS

Detailed vulnerability description

The vulnerability allows a remote attacker to obtain hash of local administrator.

The vulnerability exists due to unknown error. A remote attacker with unspecified privileges may be able to obtain password hash of local administrator. It is unclear, if the attacker should be authenticated.

Successful exploitation of the vulnerability may allow an attacker to brute-force password hash and obtain administrative privileges on vulnerable device.



How to mitigate CVE-2016-7542

The vulnerability is fixed in versions 5.2.10 GA and 5.4.2 GA.

Sources