CVE-2021-41023
published 2021-11-02CVE-2021-41023: A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.21%
11.5th percentile
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortisiemwindowsagent | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | 3.1.0 – 4.1.4 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vqp-64mp-pg5r: A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4
ghsa_unreviewed·2022-05-24
CVE-2021-41023 [MEDIUM] CWE-312 GHSA-5vqp-64mp-pg5r: A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
Fortinet
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated...
vendor_fortinet·2021-11-02·CVSS 5.5
CVE-2021-41023 [MEDIUM] CWE-522 A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated...
FG-IR-21-175: A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated...
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
CVEs: CVE-2021-41023
CWEs: CWE-522
CVSS: 5.5 (medium)
Affected products: FortiSIEM, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-02
Published