Total vulnerabilities in the database
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.
Software | From | Fixed in |
---|---|---|
fortinet / fortiportal | 5.1.0 | 5.1.2.x |
fortinet / fortiportal | 5.0.0 | 5.0.3.x |
fortinet / fortiportal | 4.2.0 | 4.2.4.x |
fortinet / fortiportal | 4.1.0 | 4.1.2.x |
fortinet / fortiportal | 6.0.0 | 6.0.6 |
fortinet / fortiportal | 5.3.0 | 5.3.7 |
fortinet / fortiportal | - | 4.0.4.x |
fortinet / fortiportal | 5.2.0 | 5.2.7 |