Total vulnerabilities in the database
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Software | From | Fixed in |
---|---|---|
fortinet / fortios | 5.2.7 | 5.2.7.x |
fortinet / fortios | 5.2.9 | 5.2.9.x |
fortinet / fortios | 5.2.1 | 5.2.1.x |
fortinet / fortios | 5.2.6 | 5.2.6.x |
fortinet / fortios | 5.4.0 | 5.4.0.x |
fortinet / fortios | 5.2.4 | 5.2.4.x |
fortinet / fortios | 5.4.1 | 5.4.1.x |
fortinet / fortios | 5.2.3 | 5.2.3.x |
fortinet / fortios | 5.2.5 | 5.2.5.x |
fortinet / fortios | 5.2.0 | 5.2.0.x |
fortinet / fortios | 5.2.2 | 5.2.2.x |
fortinet / fortios | 5.2.8 | 5.2.8.x |