Information disclosure in FortiOS - CVE-2016-7542
Published: December 2, 2016 / Updated: December 5, 2016
FortiOS
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain hash of local administrator.
The vulnerability exists due to unknown error. A remote attacker with unspecified privileges may be able to obtain password hash of local administrator. It is unclear, if the attacker should be authenticated.
Successful exploitation of the vulnerability may allow an attacker to brute-force password hash and obtain administrative privileges on vulnerable device.