CVE-2021-32591
published 2021-12-08CVE-2021-32591: A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before…
PriorityP430medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.90%
55.6th percentile
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | 5.0.0 – 5.4.4 | — |
| fortinet | fortiadc | 6.0.0 – 6.0.3 | — |
| fortinet | fortiadc | 6.1.0 – 6.1.3 | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | 5.0 – 5.6.3 | — |
| fortinet | fortimail | 6.0.0 – 6.0.11 | — |
| fortinet | fortimail | 6.2.0 – 6.2.7 | — |
| fortinet | fortimail | 6.4.0 – 6.4.5 | — |
| fortinet | fortinet_fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | 3.2.0 – 3.2.2 | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 5.7.0 – 5.7.3 | — |
| fortinet | fortiweb | 5.8.0 – 5.8.7 | — |
| fortinet | fortiweb | 6.0.0 – 6.0.7 | — |
| fortinet | fortiweb | 6.1.0 – 6.1.2 | — |
| fortinet | fortiweb | 6.2.0 – 6.2.4 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8qc7-q2w2-p7f4: A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4
ghsa_unreviewed·2021-12-09
CVE-2021-32591 [MEDIUM] CWE-327 GHSA-8qc7-q2w2-p7f4: A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Fortinet
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan...
vendor_fortinet·2021-12-08·CVSS 5.3
CVE-2021-32591 [MEDIUM] A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan...
FG-IR-20-222: A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan...
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
CVEs: CVE-2021-32591
CVSS: 5.3 (medium)
Affected products: FortiADC, FortiMail, FortiSandbox, FortiWeb
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-08
Published