CVE-2024-46665
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounti
Severity
Low 3.5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
44.5th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
Weakness: CWE-201
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Fortinet is pleased to thank Mert Gülsoy from aionet.com.tr for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.5 or above