A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2017-03-30T14:00:00
Updated: 2024-08-06T02:04:54.869Z
Reserved: 2016-09-09T00:00:00
Link: CVE-2016-7542
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-03-30T14:59:00.197
Modified: 2017-07-28T01:29:06.500
Link: CVE-2016-7542
Redhat
No data.