SB2021120720 - Information disclosure in FortiSandbox, FortiWeb and FortiADC
Published: December 7, 2021
Security Bulletin ID
SB2021120720
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Required Cryptographic Step (CVE-ID: CVE-2021-32591)
The vulnerability allows an attacker to compromise users' passwords.
The vulnerability exists due to missing cryptographic steps in the function that encrypts users' LDAP and RADIUS credentials. An attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Remediation
Install update from vendor's website.