SB2021120721 - Information disclosure in FortiMail



SB2021120721 - Information disclosure in FortiMail

Published: December 7, 2021

Security Bulletin ID SB2021120721
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing Required Cryptographic Step (CVE-ID: CVE-2021-32591)

The vulnerability allows an attacker to compromise users' passwords.

The vulnerability exists due to missing cryptographic steps in the function that encrypts users' LDAP and RADIUS credentials. An attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.