A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2017-03-30T14:00:00
Updated: 2024-10-25T14:35:34.799Z
Reserved: 2016-09-09T00:00:00
Link: CVE-2016-7542
Vulnrichment
Updated: 2024-08-06T02:04:54.869Z
NVD
Status : Modified
Published: 2017-03-30T14:59:00.197
Modified: 2017-07-28T01:29:06.500
Link: CVE-2016-7542
Redhat
No data.