CVE-2024-32122
A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclos
Severity
Low 2.1
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.5th percentile
Discovered by
Third party
Vendor advisory field
Published
Apr 8, 2025
Assigned by fortinet
Description
A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.
Weakness: CWE-257
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiOS
- Siemens · RUGGEDCOM APE1808
Credit
Fortinet is pleased to thank Vladislav Driev and Oleg Labyntsev for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.9 or above